Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-35242

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-35242?

A vulnerability has been identified in Oracle VM VirtualBox software, specifically affecting version 7.2.6. This issue can be exploited by an attacker who has high privileges and access to the infrastructure hosting VirtualBox, allowing them to compromise the virtualization product itself. While the primary impact is on Oracle VM VirtualBox, the potential for more extensive effects on other connected systems raises significant concerns. Attackers successful in exploiting this vulnerability could take over the management and functionality of Oracle VM VirtualBox, making it critical for users to address this vulnerability promptly.

Affected Version(s)

Oracle VM VirtualBox 7.2.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.