Low Privilege Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-35275

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-35275?

A vulnerability exists in Oracle VM VirtualBox that compromises its security allowing low-privileged attackers to gain unauthorized access to sensitive data. Specifically affecting version 7.2.8, this flaw can lead to unauthorized creation, deletion, or modification of data, impacting not only Oracle VM VirtualBox but also potentially extending to other related products. Addressing this vulnerability is crucial for maintaining the integrity and confidentiality of the data within the virtualized environment.

Affected Version(s)

Oracle VM VirtualBox 7.2.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.