Junglewise Threat Intelligence

CVE-2026-71138: Oracle VM VirtualBox denial of service and data access in Core component

CVE-2026-71138 · Severity: high · CVSS 7.3 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform used to run virtual machines on enterprise and consumer systems. This vulnerability allows a high-privileged local attacker with direct system access to crash the hypervisor, potentially disrupting all virtual machines running on it, and to read or modify sensitive data stored within VirtualBox. The impact extends beyond VirtualBox itself to the virtual machines it hosts, potentially affecting production workloads and customer data.

Technical details

A privilege escalation vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.14 and potentially other 7.x versions. The vulnerability is locally exploitable by a high-privileged attacker with logon access to the infrastructure. The flaw allows the attacker to cause complete denial of service (hang or repetitive crash), unauthorized read access to a subset of VirtualBox-accessible data, and unauthorized update, insert, or delete operations on some data. The scope is marked as changed, indicating that a successful exploit can significantly impact guest virtual machines and other products beyond VirtualBox itself. No patch status information is publicly available at this time.

Affected products

  • Oracle VM VirtualBox 7.2.14 and potentially other 7.x versions

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory: Oracle Critical Patch Update (August 2026)

References

Related threats