Junglewise Threat Intelligence

CVE-2026-87276: Oracle VirtualBox privilege escalation in Core

CVE-2026-87276 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

Oracle VirtualBox is a virtualization platform that allows organizations to run multiple operating systems on a single physical host. A privilege escalation vulnerability in the Core component could allow a low-privileged user with local system access to take control of VirtualBox and any virtual machines running on it, potentially exposing sensitive business operations and data.

Technical details

This is a local privilege escalation vulnerability in Oracle VirtualBox Core component affecting version 7.2.16. The vulnerability requires local attacker access with low privileges and user interaction from another person, combined with difficult exploitation conditions. The attack vector is local (AV:L) with high complexity (AC:H), and successful exploitation enables complete compromise of the VirtualBox system with scope change (affecting other products). The CVSS 3.1 vector (AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H) reflects impacts to confidentiality, integrity, and availability of the virtualization host and dependent systems.

Affected products

  • Oracle VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats