Unauthorized Access Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-71136

7.3HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71136?

A security flaw in Oracle VM VirtualBox enables a high privileged attacker with system access to exploit the virtualization platform. If successfully exploited, this vulnerability could lead to a denial of service, allowing unauthorized deletion or alteration of data within the platform. Attackers may also gain unauthorized read access to sensitive data, creating serious implications for data privacy and integrity. This issue primarily affects version 7.2.14, making timely patching crucial for users to safeguard their virtual environments.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.