CVE-2026-35246

7.5

Oracle · VM VirtualBox

A high privilege vulnerability in the Oracle VM VirtualBox Core component allows a local attacker to achieve complete system takeover and impact secondary products.

Executive summary

A critical vulnerability in Oracle VM VirtualBox version 7.2.6 permits an authenticated attacker with high privileges to compromise the host infrastructure and gain full control of the application.

Vulnerability

This vulnerability resides within the Core component of Oracle VM VirtualBox and requires an attacker to possess high privileges and local logon access to the underlying infrastructure. The flaw allows for a scope change, meaning successful exploitation can compromise not only the virtualization software but also potentially additional products running on the same host.

Business impact

The potential for complete takeover of the VirtualBox environment poses a significant threat to data confidentiality, integrity, and availability. Given the CVSS score of 7.5, the risk is substantial, particularly because the exploit can affect external products beyond the immediate software scope, potentially leading to widespread operational disruption or unauthorized access to sensitive virtualized assets.

Remediation

Immediate Action: Review the official Oracle April 2026 Critical Patch Update advisory and apply the relevant security patches as soon as they are made available by the vendor.

Proactive Monitoring: Implement strict access controls for infrastructure hosting virtualization services and monitor system logs for unauthorized attempts to escalate privileges or interact with the VirtualBox Core component.

Compensating Controls: Restrict local logon access to the virtualization host to only essential administrative accounts and utilize host-based intrusion detection systems to identify suspicious activities originating from the virtualization layer.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Although this vulnerability requires high privileges, the risk of total system takeover and scope change warrants immediate attention. Organizations should prioritize updating their Oracle VM VirtualBox installations as soon as the vendor provides a corrected version to prevent unauthorized access and potential lateral movement within the infrastructure.

More Oracle CVEs

Sources