Junglewise Threat Intelligence

CVE-2026-87271: Oracle VM VirtualBox privilege escalation in Core

CVE-2026-87271 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software used to run multiple operating systems on a single computer. A local privilege escalation vulnerability in version 7.2.16 (Windows host only) allows a user with basic system access to take complete control of the virtualization environment, potentially compromising all virtual machines and the host system. An attacker could access or modify sensitive data and disrupt operations across hosted systems.

Technical details

This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox 7.2.16 affecting Windows hosts. The vulnerability is easily exploitable and requires only low-level privileges and logon access (no special authentication bypass required). An attacker with local access can escalate privileges to achieve complete compromise (takeover) of the VirtualBox process and guest virtual machines. The attack vector is local, with low complexity, and does not require user interaction. Patch availability status is not indicated in the advisory.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats