Junglewise Threat Intelligence

CVE-2026-71141: Oracle VM VirtualBox local privilege escalation in Core component

CVE-2026-71141 · Severity: high · CVSS 7.7 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform that enables organizations to run multiple operating systems on a single physical server. A local vulnerability allows an attacker with access to the system where VirtualBox runs to gain unauthorized control over critical data and impair service availability. The attack requires user interaction and can affect the security of other systems sharing the virtualization infrastructure.

Technical details

A privilege escalation vulnerability exists in Oracle VM VirtualBox 7.2.14 and other 7.x versions in the Core component. The vulnerability is easily exploitable and requires only local access and non-attacker user interaction; no authentication credentials are needed. The attack vector is local (AV:L) with low attack complexity (AC:L). Successful exploitation allows unauthorized modification and deletion of critical data, unauthorized read access to sensitive data, and partial denial of service. The scope is changed, indicating that compromise of VirtualBox can significantly impact other products on the host system.

Affected products

  • Oracle VM VirtualBox 7, including 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats