Junglewise Threat Intelligence

CVE-2026-71132: Oracle VM VirtualBox local privilege escalation in Core

CVE-2026-71132 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform that allows organizations to run multiple operating systems on a single physical host. A local privilege escalation vulnerability in the Core component allows a high-privileged attacker with system access to gain unauthorized access to sensitive data within VirtualBox and potentially impact other systems. This could lead to exposure of virtual machine data and compromise of the hypervisor layer.

Technical details

A difficult-to-exploit local privilege escalation vulnerability exists in Oracle VM VirtualBox 7.2.14's Core component. The vulnerability requires high privileges and local access to the infrastructure, with no user interaction needed. A successful attack can result in high-impact confidentiality compromise, potentially exposing critical data accessible to VirtualBox across the infrastructure. The scope is changed, meaning the vulnerability can affect resources beyond the vulnerable component itself. No patch information is publicly available at the time of disclosure.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats