Vulnerability in Oracle VM VirtualBox Core Component by Oracle
CVE-2026-71151

5.6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71151?

A vulnerability has been identified in Oracle VM VirtualBox's core component, affecting version 7.2.14. This low-complexity flaw allows an attacker with limited privileges and access to the environment where Oracle VM VirtualBox operates to potentially compromise its security. While primarily affecting Oracle VM VirtualBox, the implications of this vulnerability may extend to other associated products, increasing the risk of unauthorized access to sensitive data. Addressing this vulnerability is critical for maintaining the integrity and confidentiality of data managed by Oracle VM VirtualBox.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.