Junglewise Threat Intelligence

CVE-2026-71128: Oracle VM VirtualBox denial of service in Core

CVE-2026-71128 · Severity: medium · CVSS 6 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that allows users to run multiple operating systems on a single computer. A vulnerability in the Core component allows a high-privileged attacker with local access to cause the application to hang or crash, disrupting virtual machine operations. While an attacker must have elevated privileges on the host system, the scope of impact extends beyond VirtualBox itself to potentially affect other products running within virtual machines.

Technical details

This is a denial-of-service vulnerability in Oracle VM VirtualBox's Core component affecting version 7.2.14 and other version 7.x releases. The vulnerability is exploitable locally (AV:L) by a high-privileged attacker (PR:H) without user interaction, requiring no complex attack conditions (AC:L). Successful exploitation results in a hang or crash (complete DoS) of VirtualBox, with impact scope extending beyond the affected product to potentially impact guest operating systems and workloads. The fix/patch status and exact root cause are not detailed in available references.

Affected products

  • Oracle VM VirtualBox 7.2.14 and other version 7.x

Timeline

  • 2026-08-18: disclosed

References

Related threats