Denial of Service Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-71139

4.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71139?

This vulnerability exists within Oracle VM VirtualBox, primarily affecting version 7.2.14. An attacker with high privileges and access to the infrastructure where the application runs could exploit this weakness. Successful exploitation can lead to the unauthorized capability to cause a hang or a persistently reproducible crash of Oracle VM VirtualBox, effectively resulting in a denial of service scenario.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.