Junglewise Threat Intelligence

CVE-2026-87270: Oracle VM VirtualBox privilege escalation in Core

CVE-2026-87270 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that runs virtual machines on Windows hosts. A privilege escalation vulnerability in the Core component allows a low-privileged local user to gain complete control over VirtualBox and any virtual machines running on it, potentially compromising hosted systems and data.

Technical details

A local privilege escalation vulnerability exists in the Core component of Oracle VM VirtualBox 7.2.16 on Windows hosts. The vulnerability is easily exploitable by a low-privileged attacker with local logon access (AV:L, PR:L, UI:N). Successful exploitation results in complete compromise of the VirtualBox process with high impact to confidentiality, integrity, and availability. The attack requires no user interaction and no special system configuration.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats