Junglewise Threat Intelligence

CVE-2026-71130: Oracle VM VirtualBox RDP remote access vulnerability in Core

CVE-2026-71130 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software used to run multiple operating systems on a single computer. A flaw in the RDP (Remote Desktop Protocol) component allows an unauthenticated attacker on the network to gain unauthorized access to sensitive data stored in virtual machines and modify some of that data, potentially compromising all guest systems running on the host.

Technical details

An easily exploitable vulnerability exists in the Core component of Oracle VM VirtualBox, exposed via the RDP protocol. The vulnerability requires no authentication and can be triggered by any network-adjacent attacker, resulting in high-impact confidentiality compromise and limited integrity impact on accessible data. The flaw affects version 7.2.14 and potentially other version 7.x releases. An attacker can gain unauthorized read access to critical data and perform unauthorized modifications to some VirtualBox-accessible data. Patch availability status is not confirmed in the advisory.

Affected products

  • Oracle VM VirtualBox 7, including 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats