Sceawere

Vulnerability Detail

CVE-2026-71141UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle VM VirtualBox Core Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox.
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-08-18T21:18:15.017Z",
  "pubdate": "2026-08-18T21:18:15.017Z",
  "executiveSummary": "A vulnerability has been identified within the Core component of Oracle VM VirtualBox version 7.2.14, presenting significant security risks to virtualized infrastructure environments. This security flaw is categorized as an easily exploitable vulnerability that can be leveraged by an unauthenticated attacker who has obtained interactive logon access to the underlying infrastructure where Oracle VM VirtualBox executes. Successful exploitation of this vulnerability mandates human interaction from a user other than the attacker, introducing a strict prerequisite for attack vector realization. The security impact of a successful exploit is comprehensive, involving a scope change that extends beyond the immediate boundaries of Oracle VM VirtualBox to potentially affect additional integrated or hosted products. The consequences of compromise encompass unauthorized creation, deletion, and modification capabilities targeting critical data or all data accessible via Oracle VM VirtualBox, alongside unauthorized read access to a subset of sensitive information. Furthermore, attackers can induce a partial denial of service condition affecting the operational availability of Oracle VM VirtualBox. With a CVSS 3.1 Base Score of 7.7, the vulnerability demonstrates substantial severity across Confidentiality, Integrity, and Availability impact metrics, necessitating immediate risk assessment and defensive prioritization by virtualization administrators.",
  "technicalDetails": "The vulnerability resides in the Core component of Oracle VM VirtualBox version 7.2.14. The attack vector is classified as local (AV:L), requiring the adversary to possess prior logon access to the host infrastructure operating system where the virtualization software is deployed. Despite requiring local infrastructure access, the attack does not necessitate pre-existing authentication (PR:N) against the VirtualBox application itself. However, successful exploitation is contingent upon user interaction (UI:R) from a distinct individual interacting with the host or guest system, serving as the trigger mechanism for the execution flow. The CVSS vector indicates a scope change (S:C), meaning the exploitation successfully breaks out of the initial security boundaries of the vulnerable component to impact secondary resources or products managed within the infrastructure. The root cause analysis points to flawed handling of internal data structures or operations within the Core component, which can be manipulated under specific user-interaction sequences. The step-by-step attack flow begins with the unauthenticated local attacker establishing a foothold on the target infrastructure. Following local access acquisition, the attacker engineers a scenario requiring targeted human interaction, such as inducing an authorized user to execute a specific application state, open a malicious file, or interact with a compromised virtual machine interface managed by the hypervisor. Upon execution of the required user interaction, the flawed Core component processes the inputs incorrectly, resulting in memory corruption, logic bypass, or improper privilege validation. This payload behavior allows the adversary to transcend intended security boundaries, granting unauthorized access rights. The post-exploitation impact includes high integrity violations through unauthorized creation, deletion, or modification of critical Oracle VM VirtualBox data assets, partial confidentiality breaches through unauthorized data read access, and partial denial of service (A:L) affecting the operational continuity of the hypervisor component."
}
CVE-2026-71141: Oracle VM VirtualBox Core Vulnerability (HIGH Severity, CVSS: 7.7) - Sceawere