CVE-2026-35230
7.5Oracle · VM VirtualBox
A critical vulnerability in the Oracle VM VirtualBox Core allows a highly privileged local attacker to achieve a full system takeover and impact additional products via scope change.
Executive summary
A high-severity vulnerability in Oracle VM VirtualBox 7.2.6 allows a local attacker with high privileges to compromise the virtualization infrastructure and potentially affect other integrated systems.
Vulnerability
The flaw exists within the Core component of Oracle VM VirtualBox and requires an attacker to possess high privileges and local logon access to the host infrastructure to trigger. Successful exploitation results in a complete takeover of the VirtualBox environment and can lead to a scope change affecting additional products.
Business impact
The exploitation of this vulnerability poses a significant risk to the integrity, confidentiality, and availability of the virtualization host. With a CVSS score of 7.5, the potential for a full takeover of the virtualization layer could lead to unauthorized access to all guest virtual machines, resulting in widespread data exposure and operational downtime for critical business services.
Remediation
Immediate Action: Monitor the official Oracle security alerts page for the release of a corrective patch and apply it to all VirtualBox instances immediately upon availability.
Proactive Monitoring: Review system access logs for unauthorized attempts to escalate privileges or anomalous interactions with the VirtualBox core processes.
Compensating Controls: Restrict administrative access to the host infrastructure to the minimum number of essential personnel and ensure that virtual environments are isolated from sensitive production networks where possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
While the requirement for high-level local access somewhat limits the attack surface, the potential for total system compromise necessitates a high level of urgency. Security teams should prioritize patching this vulnerability as soon as Oracle releases the corresponding security update to prevent potential lateral movement or full host takeover.
More Oracle CVEs
Sources
- Oracle Advisory Vendor advisory