Junglewise Threat Intelligence

CVE-2026-87275: Oracle VM VirtualBox information disclosure and denial of service in Core

CVE-2026-87275 · Severity: medium · CVSS 4.6 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform used to run multiple operating systems on a single computer. A vulnerability in its core component allows a high-privileged attacker with local access to read sensitive data and temporarily disrupt the virtualization service. This could expose confidential information from virtual machines or the host system and impact the availability of virtual environments.

Technical details

The vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.16 and affects the virtualization engine itself. It is easily exploitable by a high-privileged attacker (requiring administrative or host-level access) with local logon to the infrastructure. The attack has local attack vector (AV:L) and does not require user interaction. Successful exploitation results in unauthorized read access to a subset of VirtualBox data and the ability to cause partial denial of service. The vulnerability exhibits scope change (S:C), meaning attacks against VirtualBox can impact additional products beyond itself.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats