Executive brief
Oracle VM VirtualBox is a desktop virtualization platform that allows organizations to run multiple operating systems on a single machine. A vulnerability in its Core component allows an attacker with high privileges on the host system to read, modify, or delete sensitive data managed by VirtualBox, as well as cause partial service disruptions. This could compromise the integrity and availability of all virtual machines and data under management.
Technical details
This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox. The vulnerability is easily exploitable by a high-privileged attacker with logon access to the infrastructure running VirtualBox (local attack vector, no network access required). Successful exploitation allows unauthorized read, write, and delete access to VirtualBox-managed data, and can cause partial denial of service. The scope is marked as changed, meaning the impact extends beyond VirtualBox itself to additional products or systems under virtualization. Patch availability should be verified through Oracle's official security announcements.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed