Core Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-71132

5.3MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71132?

A security vulnerability exists in Oracle VM VirtualBox that can be exploited by a high-privileged attacker logged into the infrastructure where Oracle VM VirtualBox is running. Although contained within VirtualBox, successful exploitation can potentially lead to unauthorized access, posing significant risks to the integrity and confidentiality of sensitive data managed by the product. This vulnerability highlights the need for robust security practices to safeguard virtualization environments and prevent data breaches.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.