Junglewise Threat Intelligence

CVE-2026-71127: Oracle VM VirtualBox denial of service in Core

CVE-2026-71127 · Severity: medium · CVSS 6 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform used to run multiple virtual machines on a single physical server. A vulnerability in the Core component allows a high-privileged local attacker to crash the virtualization system, causing service downtime and disrupting all virtual machines running on the affected host. The impact extends beyond VirtualBox itself to any workloads dependent on the affected infrastructure.

Technical details

The vulnerability is a denial-of-service condition in Oracle VM VirtualBox Core component affecting version 7.2.14. It is easily exploitable and requires high privileges (administrative or hypervisor-level access) on the local infrastructure where VirtualBox runs; no network access or user interaction is required. An authenticated high-privileged attacker can trigger a hang or repeated crash of VirtualBox, causing complete service unavailability. The CVSS 3.1 vector (AV:L/AC:L/PR:H/S:C/A:H) indicates local attack vector, high privileges, and scope change with high availability impact. No patch status is publicly disclosed in the advisory.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats