Remote Denial of Service in Oracle VM VirtualBox by Oracle
CVE-2026-71137

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71137?

A vulnerability exists in Oracle VM VirtualBox that allows high-privileged attackers, with access to the infrastructure where VirtualBox runs, to compromise the application. This flaw can lead to unauthorized actions, resulting in persistent crashes or denial of service for the affected virtual environment. Effective exploitation of this vulnerability has implications that extend beyond VirtualBox itself, potentially influencing other products in the system's ecosystem.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.