Junglewise Threat Intelligence

CVE-2026-71151: Oracle VM VirtualBox privilege escalation via Core component

CVE-2026-71151 · Severity: medium · CVSS 5.6 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform used to run multiple operating systems on a single physical server. An authenticated attacker with local access to the host system can exploit a flaw in the Core component to gain unauthorized access to sensitive data managed by VirtualBox, potentially exposing confidential information and affecting other systems running on that infrastructure.

Technical details

This is a local privilege escalation vulnerability in the Oracle VM VirtualBox Core component affecting version 7.2.14. The vulnerability is difficult to exploit and requires the attacker to have low-privilege local access and logon to the infrastructure where VirtualBox is running. Successful exploitation allows an attacker to read sensitive data accessible to VirtualBox, with potential scope change that could impact additional products running on the same infrastructure. The vulnerability is primarily a confidentiality issue with no impact on integrity or availability. A patch addressing CVE-2026-71151 is expected in Oracle's security updates.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats