Vulnerability in Oracle VM VirtualBox Product by Oracle
CVE-2026-87281

3.2LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87281?

A vulnerability exists within Oracle VM VirtualBox, specifically in its core component, impacting version 7.2.16. The flaw allows attackers with elevated privileges, who are logged into the infrastructure hosting Oracle VM VirtualBox, to exploit the system. Although primarily affecting Oracle VM VirtualBox, successful exploitation can lead to unauthorized access to sensitive data, potentially affecting other interrelated products. The implications of this vulnerability emphasize the need for prompt remediation and heightened security measures to safeguard critical data.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.