Junglewise Threat Intelligence

CVE-2026-87281: Oracle VM VirtualBox information disclosure in Core

CVE-2026-87281 · Severity: low · CVSS 3.2 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that runs on servers and workstations to create and manage virtual machines. This vulnerability allows a high-privileged local attacker to read sensitive data from VirtualBox's internal structures, potentially exposing information about virtual machines and their configuration. The issue requires local system access and elevated privileges to exploit.

Technical details

The vulnerability is an information disclosure flaw in Oracle VM VirtualBox version 7.2.16 affecting the Core component. It requires high privilege level access (PR:H) and local attack vector (AV:L), with no user interaction necessary. An attacker with local administrative or privileged account access can read a subset of VirtualBox-accessible data, potentially exposing sensitive information about virtual machine configurations or internal state. The scope is changed (S:C), meaning attacks may impact systems beyond VirtualBox itself. No public patch availability information is provided in the advisory.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats