Sceawere

Vulnerability Detail

CVE-2026-71115UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle VM VirtualBox Core Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Attack Type
Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.0",
  "pubDate": "2026-08-18T21:18:12.103Z",
  "pubdate": "2026-08-18T21:18:12.103Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Core component of Oracle VM VirtualBox version 7.2.14, which can lead to significant security compromises despite requiring specific privileges. The flaw allows an attacker possessing high-level privileges and local logon access to the underlying infrastructure where Oracle VM VirtualBox executes to compromise the application. Although the vulnerability resides natively within Oracle VM VirtualBox, successful exploitation generates a scope change, meaning attacks may significantly impact additional products and system layers beyond the immediate hypervisor boundaries. The primary impact of this vulnerability is directed at data confidentiality, resulting in unauthorized access to critical data or complete access to all data accessible by Oracle VM VirtualBox. Given the CVSS 3.1 Base Score of 6.0 with the vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N, the risk profile emphasizes severe confidentiality breaches facilitated by local vector access. Organizations utilizing the affected version must evaluate the risk posed by highly privileged local entities and implement strict access controls to prevent unauthorized data exposure across the virtualized infrastructure.",
  "technicalDetails": "The vulnerability resides in the Core component of Oracle VM VirtualBox version 7.2.14, representing a weakness that can be leveraged by a malicious actor who has already achieved high privileges on the host infrastructure. The attack vector is strictly local (AV:L), meaning the adversary must have direct logon access to the host system running the Oracle VM VirtualBox software. The attack complexity is rated as low (AC:L), indicating that no specialized race conditions or complex environmental setups are required to execute the exploit once access is secured. Furthermore, user interaction is not required (UI:N), allowing the attack to proceed autonomously upon initiation by the privileged user. A critical characteristic of this vulnerability is the scope change (S:C), which implies that the security scope extends beyond the vulnerable Oracle VM VirtualBox boundary to potentially impact other associated components, virtual machines, or infrastructure products managed by the environment. The authentication and privilege requirements mandate high privileges (PR:H), meaning the attacker must operate with administrative or root-equivalent access to the underlying infrastructure to initiate the attack sequence. From a payload and impact perspective, the vulnerability strictly affects confidentiality (C:H) with no direct impact on integrity (I:N) or availability (A:N). Consequently, successful exploitation grants the attacker unauthorized access to critical data or complete access to all data repositories and memory spaces accessible by Oracle VM VirtualBox. The step-by-step attack flow begins with the attacker establishing a local, highly privileged session on the virtualization host. Leveraging this high-privilege context, the adversary interacts with the vulnerable Core component of Oracle VM VirtualBox 7.2.14. By sending crafted inputs or manipulating internal control structures within the Core component, the attacker bypasses standard isolation boundaries, culminating in the unauthorized disclosure and extraction of sensitive data protected by the virtualization layer, thereby fulfilling the criteria for a severe confidentiality breach across the affected scope."
}
CVE-2026-71115: Oracle VM VirtualBox Core Vulnerability (MEDIUM Severity, CVSS: 6.0) - Sceawere