Vulnerability in Oracle VM VirtualBox Affects Oracle's Virtualization Products
CVE-2026-35251

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-35251?

A security vulnerability has been identified in Oracle VM VirtualBox, specifically affecting version 7.2.6. This vulnerability allows a high-privileged attacker with logon access to the infrastructure to compromise the virtual machine environment. Although the flaw resides within Oracle VM VirtualBox, successful exploitation may extend its impact to other associated systems. Attackers leveraging this vulnerability can effectively take control of Oracle VM VirtualBox, leading to significant operational consequences and potential data exposure.

Affected Version(s)

Oracle VM VirtualBox 7.2.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.