Junglewise Threat Intelligence

CVE-2026-71139: Oracle VM VirtualBox denial of service in Core

CVE-2026-71139 · Severity: medium · CVSS 4.4 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that runs virtual machines on physical hosts. A vulnerability in its Core component allows a high-privilege local attacker to crash the virtualization platform, causing downtime and disrupting all virtual machines running on the affected host. This requires local access and administrative privileges, limiting the attack surface to insider threats or compromised accounts with high-level system access.

Technical details

This is a denial-of-service vulnerability in the Core component of Oracle VM VirtualBox version 7.2.14, triggered by a local attack vector requiring high privilege (logon to the infrastructure). The vulnerability allows an authenticated high-privilege attacker to cause a hang or crash (complete DOS) of the VirtualBox process. The attack has low complexity and no user interaction required. The CVSS 3.1 score of 4.4 reflects impact limited to availability with no confidentiality or integrity compromise. Patches are expected from Oracle's regular security updates.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats