Junglewise Threat Intelligence

CVE-2026-71126: Oracle VM VirtualBox privilege escalation in Core

CVE-2026-71126 · Severity: high · CVSS 7.8 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a widely-used virtualization platform that allows organizations to run multiple operating systems on a single physical machine. This vulnerability allows a low-privileged user with local access to the host system to gain complete control over VirtualBox, potentially compromising all virtual machines and their data. The impact extends beyond VirtualBox itself, affecting the security of guest operating systems and any workloads running within them.

Technical details

This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox. The vulnerability is difficult to exploit and requires the attacker to have low-level logon access to the infrastructure hosting VirtualBox, with no user interaction required. Successful exploitation can result in complete takeover of VirtualBox, with scope change indicating that impacts extend to other products and systems running within the hypervisor. The CVSS vector reflects high impact across confidentiality, integrity, and availability. Patches should be available from Oracle; users should upgrade from the affected version 7.2.14 to a patched release.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats