Core Vulnerability in Oracle VM VirtualBox 7.2.16 by Oracle
CVE-2026-87278

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87278?

A vulnerability has been identified in Oracle VM VirtualBox 7.2.16 that could be exploited by an unauthenticated attacker who has access to the infrastructure where VirtualBox is running. It allows the attacker to cause a denial of service, resulting in the application hanging or crashing frequently. Furthermore, the vulnerability may allow unauthorized manipulation of data within Oracle VM VirtualBox, including the ability to update, insert, or delete accessible data. Human interaction from a user other than the attacker is required for successful exploitation.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.