Privilege Escalation Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-60155

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60155?

A vulnerability exists in Oracle VM VirtualBox, specifically in version 7.2.12, which allows a high privileged attacker with access to the infrastructure where VirtualBox operates to gain unauthorized control. Although the core issue resides within Oracle VM VirtualBox, its exploitation can lead to significant impacts across related products, indicating a broad attack surface. Successful exploitation may enable the attacker to gain comprehensive control of Oracle VM VirtualBox, compromising system security and integrity.

Affected Version(s)

Oracle VM VirtualBox 7.2.12

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.