CVE-2026-60161: Race Condition
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle VM VirtualBox (Core)to a version that resolves this vulnerability.Fixed in 7.2.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60161?
CVE-2026-60161 has a medium severity rating of 6.1.
How do I fix CVE-2026-60161?
To fix CVE-2026-60161, update Oracle VM VirtualBox to the latest version provided by Oracle.
What type of vulnerability is CVE-2026-60161?
CVE-2026-60161 is classified as a Race Condition vulnerability.
Who is affected by CVE-2026-60161?
CVE-2026-60161 affects users running Oracle VM VirtualBox version 7.2.12.
What potential impact does CVE-2026-60161 have?
CVE-2026-60161 allows an unauthenticated attacker to compromise the Oracle VM VirtualBox environment.