Oracle VM VirtualBox Core Vulnerability Allowing Unauthorized Access
CVE-2026-71138

7.3HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71138?

A vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with logon access to compromise the system. This flaw can lead to unauthorized access that may facilitate a denial of service attack, allowing the attacker to cause repeatable crashes or hangs of the virtualization service. Additionally, it may permit modifications to accessible data and unauthorized read access to a subset of that data, thereby impacting the confidentiality, integrity, and availability of data within the platform. The risk extends beyond VirtualBox, possibly affecting other Oracle products integrated with it.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.