Vulnerability in Oracle VM VirtualBox Component by Oracle
CVE-2026-71134

5.7MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71134?

A security vulnerability has been identified in the Oracle VM VirtualBox product, specifically in its core component. This issue affects version 7.2.14 and poses a threat by allowing a high-privileged attacker who has access to the Oracle VM VirtualBox infrastructure to compromise the system. The implications of this vulnerability extend beyond just the VirtualBox application; successful exploitation can result in unauthorized modifications to data, including the ability to insert, update, or delete accessible information. Additionally, it allows for unauthorized reading of certain accessible data and the potential to induce a partial denial of service, thereby affecting overall functionality. Organizations utilizing Oracle VM VirtualBox should assess their security posture and implement necessary measures to mitigate these risks.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.