Vulnerability in Oracle VM VirtualBox for Windows by Oracle
CVE-2026-87269

7.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87269?

A vulnerability in Oracle VM VirtualBox could allow a low-privileged attacker, who is logged onto the infrastructure where Oracle VM VirtualBox operates, to successfully compromise the system. Once exploited, this vulnerability might lead to unauthorized control over the VirtualBox environment. This particular issue is pertinent to Windows host installations, emphasizing the need for stringent security measures to ensure the integrity and confidentiality of the virtual machines utilized.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.