Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Fri, 21 Aug 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Exploit Enables Unauthorized Access to VirtualBox 7.2.14 |
Thu, 20 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Exploit Enables Unauthorized Access to VirtualBox 7.2.14 | |
| Weaknesses | CWE-284 |
Thu, 20 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Access Exploit Allows Unauthorized Data Access in Oracle VM VirtualBox 7.2.14 | |
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Access Exploit Allows Unauthorized Data Access in Oracle VM VirtualBox 7.2.14 | |
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation and Data Access Vulnerability in Oracle VM VirtualBox 7.2.14 | |
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation and Data Access Vulnerability in Oracle VM VirtualBox 7.2.14 | |
| Weaknesses | CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle vm Virtualbox |
|
| CPEs | cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle vm Virtualbox |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:03:40.803Z
Updated: 2026-08-20T17:59:18.122Z
Reserved: 2026-08-04T22:06:34.619Z
Link: CVE-2026-71132
Updated: 2026-08-20T17:47:33.631Z
Status : Analyzed
Published: 2026-08-18T21:18:14.083
Modified: 2026-08-26T17:57:34.363
Link: CVE-2026-71132
No data.