Core Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-71141

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71141?

An exploitable vulnerability exists in Oracle VM VirtualBox that allows an unauthenticated attacker with access to the infrastructure where VirtualBox runs to compromise the system. While the vulnerability is contained within VirtualBox, successful exploitation can lead to unauthorized creation, deletion, or modification of access to critical data. Additionally, it allows unauthorized reading of certain data and the ability to induce partial denial of service. The attack requires human interaction from a person besides the attacker. As a result, this vulnerability poses significant risks to system integrity and data availability.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.