CVE-2026-71125: Medium severity Oracle Oracle VM VirtualBox vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle VM VirtualBox (Core)to a version that resolves this vulnerability.Fixed in 7.2.14
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs logon access to the infrastructure where Oracle VM VirtualBox is running. No privileges are required, but exploitation also requires interaction by someone other than the attacker.
Which deployments should be checked first?
Check systems running the supported affected Oracle VM VirtualBox version 7.2.14. The attack vector is local, so prioritize environments where untrusted or less-trusted users can log on to the infrastructure hosting VirtualBox.