Sceawere

Vulnerability Detail

CVE-2026-71138UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle VM VirtualBox Core Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Attack Type
Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-18T21:18:14.677Z",
  "pubdate": "2026-08-18T21:18:14.677Z",
  "executiveSummary": "A vulnerability exists within the Core component of Oracle VM VirtualBox version 7.2.14, presenting significant risks to system integrity, confidentiality, and availability. The flaw is categorized as an easily exploitable vulnerability that requires a high-privileged attacker with local logon access to the underlying infrastructure where Oracle VM VirtualBox executes. Although the primary flaw resides within the virtualization software itself, a successful attack exhibits a scope change, meaning the impact extends beyond the immediate VirtualBox boundary to significantly affect additional co-resident products or infrastructure components. The attacker capabilities involve unauthorized execution against the hypervisor or core virtualization engine, leading to severe operational disruptions. Specifically, successful exploitation can result in a complete denial of service characterized by a system hang or frequently repeatable application crash. Furthermore, adversaries can achieve unauthorized read access to a subset of accessible data, as well as unauthorized update, insert, or delete capabilities regarding targeted Oracle VM VirtualBox accessible data structures. Given the high-privileged prerequisite, organizations must evaluate their local access controls and infrastructure hardening to mitigate potential lateral movement or cascading infrastructure degradation stemming from this core virtualization flaw.",
  "technicalDetails": "The vulnerability resides in the Core component of Oracle VM VirtualBox version 7.2.14, specifically involving insufficient access controls, boundary validation, or resource management within the virtualization engine running on the host infrastructure. The attack vector is strictly local (AV:L), meaning the adversary must already possess physical or remote interactive logon access to the operating system or infrastructure layer hosting the VirtualBox execution environment. The attack complexity is rated as low (AC:L), indicating that once the prerequisite privileges are met, no specialized race conditions or complex environmental states are required to reliably trigger the flaw. The privilege requirement is high (PR:H), necessitating that the threat actor operates with elevated administrative or root-level privileges on the host infrastructure to interact with the vulnerable Core component interfaces. No user interaction is required (UI:N) to successfully execute the attack.\nThe attack flow begins with the high-privileged actor leveraging their local access to interact directly with the Oracle VM VirtualBox Core component APIs, shared memory spaces, control devices, or driver interfaces. Because the vulnerability involves a scope change (S:C), the execution context or security authority boundaries breached by the attacker extend outward from the immediate virtualization process to impact secondary components or adjacent resources within the infrastructure. Upon successfully supplying maliciously crafted inputs, parameters, or control commands to the vulnerable Core component, the attacker achieves unauthorized data manipulation. This manifests as unauthorized read access to a subset of sensitive data accessible by Oracle VM VirtualBox, alongside unauthorized update, insert, or delete capabilities against stored or in-memory data structures.\nIn addition to data compromise, the payload behavior triggers catastrophic availability failures within the targeted environment. The exploitation results in an unauthorized ability to induce an immediate hang or a frequently repeatable application and system crash, culminating in a complete denial of service (A:H) for Oracle VM VirtualBox and potentially impacting the broader infrastructure due to the scope change. The CVSS 3.1 vector evaluates to (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H), yielding a high base score of 7.3. The combination of low attack complexity and severe availability and integrity consequences makes this vulnerability critical for environments hosting mission-critical virtualized workloads."
}
CVE-2026-71138: Oracle VM VirtualBox Core Vulnerability (HIGH Severity, CVSS: 7.3) - Sceawere