Junglewise Threat Intelligence

CVE-2026-87268: Oracle VM VirtualBox privilege escalation in Core

CVE-2026-87268 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a widely-used virtualization platform that allows organizations to run multiple operating systems on a single physical computer. A vulnerability in the Core component allows a low-privileged user with access to the host system to escalate privileges and take complete control of the hypervisor, affecting only Windows hosts. Successful exploitation could allow an attacker to compromise all virtual machines running on the affected host.

Technical details

This is a local privilege escalation vulnerability in the Oracle VM VirtualBox Core component affecting version 7.2.16 on Windows hosts. The vulnerability is easily exploitable and requires only low privileges and logon access to the host—no user interaction or special configuration is needed. An authenticated local attacker can exploit this to achieve complete compromise of the VirtualBox process, with impacts on confidentiality, integrity, and availability of all guest systems. The vulnerability appears to be unpatched as of the advisory date (2026-09-15); users should monitor Oracle's security advisories for patch releases.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats