Core Vulnerability in Oracle VM VirtualBox Affects Oracle Virtualization
CVE-2026-35247

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-35247?

An exploitable vulnerability has been identified in Oracle VM VirtualBox, affecting version 7.2.6. This core security flaw allows a high-privileged attacker with access to the hosting infrastructure to potentially compromise the entire Oracle VM VirtualBox environment. While the direct implications are on the VirtualBox itself, the ramifications could extend to other products integrated within the system. Successful exploitation may lead to unauthorized access to sensitive data or even complete control over all data accessible via Oracle VM VirtualBox instances.

Affected Version(s)

Oracle VM VirtualBox 7.2.6

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.