Sceawere

Vulnerability Detail

CVE-2026-71116UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle VM VirtualBox Core Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox.
Vector String
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T21:18:12.223Z",
  "pubdate": "2026-08-18T21:18:12.223Z",
  "executiveSummary": "A difficult to exploit vulnerability exists within the Core component of Oracle VM VirtualBox version 7.2.14, which can lead to the complete compromise of the virtualization platform.\nThe security flaw requires a highly privileged attacker who already possesses interactive logon access to the underlying infrastructure where Oracle VM VirtualBox executes.\nDespite the localized execution vector, a successful exploit triggers a scope change, allowing malicious operations to significantly impact additional products and system boundaries beyond the immediate virtualization container.\nSuccessful exploitation results in the total takeover of Oracle VM VirtualBox, yielding high-severity impacts across confidentiality, integrity, and availability with a CVSS 3.1 base score of 7.5.\nGiven the requirement for elevated pre-existing privileges and high attack complexity, risk implications primarily concern lateral movement, hypervisor breakout scenarios, or infrastructure-wide administrative degradation originating from compromised host access.",
  "technicalDetails": "The vulnerability resides in the Core component of Oracle VM VirtualBox version 7.2.14, specifically involving internal resource management or inter-process communication interfaces handling hypervisor operations.\nExploitation requires the adversary to authenticate locally to the host operating system or virtualization layer with high privileges (PR:H) and successfully execute complex procedural actions (AC:H) under zero user interaction constraints (UI:N).\nThe attack vector is strictly local (AV:L), meaning network exposure is not a direct prerequisite; however, the vulnerability leverages local execution contexts to interact with privileged system daemons, drivers, or hypervisor control interfaces.\nThe attack flow begins with the highly privileged local attacker establishing execution capability within the infrastructure hosting Oracle VM VirtualBox. By leveraging specialized inputs or manipulating shared core structures, the adversary subverts the intended security boundaries enforced by the virtualization engine.\nDue to the scope change characteristic (S:C) of this flaw, successful payload execution transcends the immediate boundaries of the Oracle VM VirtualBox process, affecting secondary products and dependent infrastructure components residing on the same physical or virtualized host.\nPost-exploitation impact includes the full takeover of Oracle VM VirtualBox, granting the attacker arbitrary code execution capabilities with hypervisor-level privileges, thereby compromising the confidentiality, integrity, and availability of all managed virtual machines and associated core services."
}
CVE-2026-71116: Oracle VM VirtualBox Core Privilege Escalation (HIGH Severity, CVSS: 7.5) - Sceawere