Junglewise Threat Intelligence

CVE-2026-87273: Oracle VM VirtualBox privilege escalation in Core

CVE-2026-87273 · Severity: high · CVSS 8.6 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform that allows organizations to run multiple operating systems on a single physical server. A vulnerability in the Core component allows a local attacker with system access to take complete control of the hypervisor, potentially compromising all virtual machines running on the affected host and the underlying infrastructure.

Technical details

This is a local privilege escalation vulnerability in Oracle VM VirtualBox Core component affecting version 7.2.16. The vulnerability is easily exploitable and requires the attacker to have local logon access to the infrastructure and requires user interaction from another person. The attack vector is local (AV:L), with no special privileges required (PR:N), but requires user interaction (UI:R). Successful exploitation results in complete system compromise with high confidentiality, integrity, and availability impact. The vulnerability exhibits scope change (S:C), meaning an attacker can impact resources beyond the vulnerable component itself. Patch availability is indicated by the advisory publication.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats