Remote Execution Flaw in Oracle VM VirtualBox by Oracle
CVE-2026-71127

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71127?

The vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with access to the infrastructure to exploit the product. When successfully exploited, the attacker can cause significant disruptions, including the potential for system crashes and denial of service (DoS). This vulnerability primarily affects Oracle VM VirtualBox version 7.2.14 but can also impact other interconnected products, leading to increased operational risks. Organizations using affected versions must implement necessary security patches and best practices to mitigate potential threats.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.