Unauthenticated Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-60161

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60161?

An unauthenticated vulnerability has been identified in Oracle VM VirtualBox, allowing attackers with logon to the infrastructure where it operates to compromise the system. This vulnerability can lead to unauthorized updates, data manipulation, and even Denial of Service, resulting in system crashes. Successful exploitation requires human interaction from a third party, highlighting the importance of user awareness and secure operational practices.

Affected Version(s)

Oracle VM VirtualBox 7.2.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.