Denial of Service Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-87274

4.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87274?

A vulnerability has been identified in Oracle VM VirtualBox that allows a low privileged attacker, who has access to the infrastructure where Oracle VM VirtualBox runs, to exploit the system. This vulnerability necessitates human interaction from an individual other than the attacker, leading to a scenario where successful exploitation can cause the application to hang or crash repeatedly. Such attacks can disrupt the availability of Oracle VM VirtualBox, potentially resulting in denial of service for users. The affected version is 7.2.16, highlighting the importance of ensuring systems are updated and monitored for potential exploitation.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.