AI analysis
CVE-2026-71114 is an information disclosure vulnerability in the Core component of Oracle VM VirtualBox; the ZDI advisory characterizes it as an out-of-bounds read in the VirtioSCSI component (Oracle classifies it under CWE-284, improper access control). It is triggered by an attacker who already has a high-privileged logon on the infrastructure where VirtualBox runs, requires no user interaction, and is rated easily exploitable. Successful attacks yield unauthorized access to critical data, potentially all data accessible to VirtualBox, and the scope change means the impact can extend to additional products beyond VirtualBox itself, though integrity and availability are unaffected. Any deployment running the affected 7.2.14 release of the 7.2 branch is exposed, including desktop hosts and test lab servers where users or automation hold privileged local accounts. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.2%.
What to do: Upgrade VirtualBox 7.2.14 installations to the patched release published in Oracle's Critical Patch Update (check the Oracle Virtualization CPU advisory for the exact fixed 7.2.x version). Until patched, restrict high-privileged local logon access on VirtualBox hosts to trusted administrators and review what host resources VirtualBox can access. Note the scope change: treat exposed credentials or sensitive data readable by VirtualBox as potentially exposed to other products on the same infrastructure.
Affected
| Oracle VM VirtualBox (Core) | 7.2.14 (the only supported version listed as affected) |
Estimated exposure
largelikely hundreds of thousands of hosts on VirtualBox 7.2.x (no official install counts) — VirtualBox is one of the most widely deployed free desktop hypervisors with millions of cumulative installs among developers and test environments, but the flaw is limited to the 7.2.14 maintenance release of the 7.2 branch, so the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).