Sceawere

Vulnerability Detail

CVE-2026-71136UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle VM VirtualBox Core Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Attack Type
Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-18T21:18:14.440Z",
  "pubdate": "2026-08-18T21:18:14.440Z",
  "executiveSummary": "A vulnerability exists within the Core component of Oracle VM VirtualBox version 7.2.14, allowing a highly privileged attacker with local logon access to compromise the virtualization infrastructure.\nThe vulnerability is characterized by a high severity CVSS 3.1 base score of 7.3 with the vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H, indicating local attack vector, low complexity, high privilege requirements, and no user interaction required with a changed security scope.\nSuccessful exploitation of this flaw can lead to a complete denial of service through application hangs or repeatable crashes, alongside unauthorized read, update, insert, and delete access to a subset of accessible data.\nDue to the scope change vector, successful attacks targeting Oracle VM VirtualBox may significantly impact additional interconnected products within the virtualization infrastructure.\nMitigation requires applying vendor-supplied updates or implementing strict administrative controls to limit high-privileged local access to the underlying virtualization host.",
  "technicalDetails": "The vulnerability resides in the Core component of Oracle VM VirtualBox 7.2.14, affecting internal data structures, hypervisor management routines, or core virtualization handling mechanisms.\nThe attack vector is local (AV:L), meaning the adversary must already have established an interactive logon session on the underlying infrastructure hosting the Oracle VM VirtualBox application.\nThe attack complexity is low (AC:L), and no user interaction (UI:N) is required to successfully trigger the flaw once pre-requisites are met.\nPrivilege requirements are high (PR:H), necessitating administrative or equivalent privileges within the host infrastructure to access the vulnerable interfaces or components exposed by the Core module.\nThe attack flow begins with the authenticated high-privileged attacker leveraging local execution capabilities to interact with vulnerable internal APIs, shared memory spaces, or control routines managed by the Core component.\nUpon reaching the vulnerable execution path, the payload or specially crafted input triggers improper handling of data structures or resource management operations.\nThis malformed interaction results in memory corruption, invalid state transitions, or unhandled exceptions within the hypervisor runtime.\nThe post-exploitation impact includes availability degradation manifested as application hangs or frequently repeatable crashes resulting in a complete Denial of Service (complete DOS) of Oracle VM VirtualBox.\nAdditionally, the confidentiality and integrity vectors are impacted, granting unauthorized read, update, insert, or delete access to a subset of data accessible to Oracle VM VirtualBox.\nDue to the scope change (S:C) attribute, the impact extends beyond the immediate boundary of Oracle VM VirtualBox, potentially compromising the security posture of additional adjacent products or underlying host components."
}
CVE-2026-71136: Oracle VM VirtualBox Core Vulnerability (HIGH Severity, CVSS: 7.3) - Sceawere