Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). (CVE-2026-71115)
A vulnerability exists in Oracle VM VirtualBox version 7.2.14 that allows a high privileged attacker with local access to compromise the VirtualBox environment. The vulnerability impacts confidentiality and can lead to unauthorized access to critical data within Oracle VM VirtualBox. The CVSS 3.1 base score is 6.0, indicating a medium severity issue. No known exploits in the wild have been reported. The vulnerability affects multiple specific versions of VirtualBox, primarily older versions including 7.2.14 and many earlier builds. Oracle has released a Critical Security Patch Update in August 2026 addressing this and other vulnerabilities, and customers are strongly advised to apply available patches promptly.
AI Analysis
Technical Summary
CVE-2026-71115 is a vulnerability in the core component of Oracle VM VirtualBox, specifically affecting version 7.2.14 and numerous other detailed versions. It allows a high privileged attacker with local access (logon) to the infrastructure where VirtualBox runs to compromise the product. The vulnerability has a confidentiality impact with no integrity or availability impact. The CVSS 3.1 vector is AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N, reflecting local attack vector, low complexity, high privileges required, no user interaction, scope changed, and high confidentiality impact. Oracle's August 2026 Critical Security Patch Update includes fixes for this vulnerability among many others, and Oracle strongly recommends applying these patches without delay.
Potential Impact
Successful exploitation can result in unauthorized access to critical data within Oracle VM VirtualBox, potentially compromising confidentiality. The vulnerability requires high privileges and local access to the system. There is no reported impact on integrity or availability. The scope of the vulnerability extends beyond just VirtualBox, potentially affecting additional Oracle products that interact with it.
Mitigation Recommendations
Oracle has released a Critical Security Patch Update in August 2026 that addresses this vulnerability. Users are strongly advised to apply the official Oracle patches promptly to mitigate the risk. No alternative mitigations or workarounds are specified. Maintaining up-to-date patches is critical as Oracle reports that some successful attacks have occurred due to failure to apply available patches.
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). (CVE-2026-71115)
Description
A vulnerability exists in Oracle VM VirtualBox version 7.2.14 that allows a high privileged attacker with local access to compromise the VirtualBox environment. The vulnerability impacts confidentiality and can lead to unauthorized access to critical data within Oracle VM VirtualBox. The CVSS 3.1 base score is 6.0, indicating a medium severity issue. No known exploits in the wild have been reported. The vulnerability affects multiple specific versions of VirtualBox, primarily older versions including 7.2.14 and many earlier builds. Oracle has released a Critical Security Patch Update in August 2026 addressing this and other vulnerabilities, and customers are strongly advised to apply available patches promptly.
CVSS v3.1
Score 6.0medium
Affected software
pkg:deb/ubuntu/virtualbox?arch=source&distro=xenialpkg:deb/ubuntu/virtualbox?arch=source&distro=bionicpkg:deb/ubuntu/virtualbox?arch=source&distro=focalpkg:deb/ubuntu/virtualbox?arch=source&distro=jammypkg:deb/ubuntu/virtualbox?arch=source&distro=noblepkg:deb/ubuntu/virtualbox?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-71115 is a vulnerability in the core component of Oracle VM VirtualBox, specifically affecting version 7.2.14 and numerous other detailed versions. It allows a high privileged attacker with local access (logon) to the infrastructure where VirtualBox runs to compromise the product. The vulnerability has a confidentiality impact with no integrity or availability impact. The CVSS 3.1 vector is AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N, reflecting local attack vector, low complexity, high privileges required, no user interaction, scope changed, and high confidentiality impact. Oracle's August 2026 Critical Security Patch Update includes fixes for this vulnerability among many others, and Oracle strongly recommends applying these patches without delay.
Potential Impact
Successful exploitation can result in unauthorized access to critical data within Oracle VM VirtualBox, potentially compromising confidentiality. The vulnerability requires high privileges and local access to the system. There is no reported impact on integrity or availability. The scope of the vulnerability extends beyond just VirtualBox, potentially affecting additional Oracle products that interact with it.
Mitigation Recommendations
Oracle has released a Critical Security Patch Update in August 2026 that addresses this vulnerability. Users are strongly advised to apply the official Oracle patches promptly to mitigate the risk. No alternative mitigations or workarounds are specified. Maintaining up-to-date patches is critical as Oracle reports that some successful attacks have occurred due to failure to apply available patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-71115
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a870a95acd9273b49b5a558
Added to database: 08/20/2026, 14:09:25 UTC
Last enriched: 08/20/2026, 15:21:04 UTC
Last updated: 08/21/2026, 03:51:58 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.