Vulnerability in Oracle VM VirtualBox Affects Oracle's Virtualization Component
CVE-2026-47053

5.6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47053?

A vulnerability exists within Oracle VM VirtualBox that allows a low privileged attacker with access to the infrastructure to manipulate the virtualization environment. Successful exploitation necessitates human interaction from a user not involved in the attack, allowing unauthorized creation, deletion, or modification of critical data accessible to Oracle VM VirtualBox. Additionally, this vulnerability could enable a partial denial of service, impacting the overall functionality of the virtualization component.

Affected Version(s)

Oracle VM VirtualBox 7.2.12

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.