Junglewise Threat Intelligence

CVE-2026-71140: Oracle VM VirtualBox data access vulnerability in Core

CVE-2026-71140 · Severity: low · CVSS 3.4 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that allows organizations to run multiple operating systems on a single physical computer. A vulnerability in version 7.2.14 allows a high-privileged local attacker to read sensitive data and make unauthorized changes to VirtualBox configuration or data. An attacker with administrative access to the host machine could exploit this to view or modify virtual machine settings or other sensitive information.

Technical details

This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox version 7.2.14. The vulnerability requires high-level privileges (PR:H) and local system access (AV:L), with no user interaction needed. An attacker with existing elevated privileges on the host machine can achieve unauthorized read and write access to a subset of VirtualBox data, compromising both confidentiality and integrity. The CVSS 3.1 score is 3.4, reflecting low overall severity due to the high privilege requirement.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats