Junglewise Threat Intelligence

CVE-2026-71137: Oracle VM VirtualBox denial of service in Core

CVE-2026-71137 · Severity: medium · CVSS 6 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that runs virtual machines on host computers. This vulnerability allows a privileged local attacker to crash VirtualBox and render virtual machines unavailable, disrupting operations and potentially affecting multiple systems. The attack requires administrative-level access to the host system where VirtualBox is running.

Technical details

This vulnerability in the VirtualBox Core component is an easily exploitable denial-of-service flaw requiring high privilege (root/administrative) access and local logon to the infrastructure. The attack vector is local (AV:L) with no user interaction required. Successful exploitation causes a hang or crash of VirtualBox (complete availability impact), with scope change indicating secondary impact on additional products. The CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H) reflects a base score of 6.0 with no confidentiality or integrity impact, only availability.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats