Junglewise Threat Intelligence

CVE-2026-71129: Oracle VM VirtualBox privilege escalation in Core

CVE-2026-71129 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform that allows organizations to run multiple virtual machines on a single physical server. This vulnerability allows a high-privileged local user to compromise the entire VirtualBox hypervisor and potentially impact other virtual machines running on the same host. Successful exploitation could lead to complete system takeover and unauthorized access to all virtualized environments.

Technical details

This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox version 7.2.14. The vulnerability requires high-level privileges and local logon access to the infrastructure, with no user interaction needed. An attacker with these elevated privileges can exploit this flaw to achieve full compromise of VirtualBox, with scope change indicating potential impact on other products running on the same system. The attack vector is local (AV:L), has low attack complexity (AC:L), requires high privileges (PR:H), and results in high confidentiality, integrity, and availability impacts. Patch availability and specific technical details are not publicly disclosed in the reference materials.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats