ZeroHour

CVE-2026-71114

large

Out-of-Bounds Read Information Disclosure in Oracle VM VirtualBox VirtioSCSI

CVSS 3.1
6.0 medium
EPSS
<1%p6
Published
()
Modified
AI analysis

CVE-2026-71114 is an information disclosure vulnerability in the Core component of Oracle VM VirtualBox; the ZDI advisory characterizes it as an out-of-bounds read in the VirtioSCSI component (Oracle classifies it under CWE-284, improper access control). It is triggered by an attacker who already has a high-privileged logon on the infrastructure where VirtualBox runs, requires no user interaction, and is rated easily exploitable. Successful attacks yield unauthorized access to critical data, potentially all data accessible to VirtualBox, and the scope change means the impact can extend to additional products beyond VirtualBox itself, though integrity and availability are unaffected. Any deployment running the affected 7.2.14 release of the 7.2 branch is exposed, including desktop hosts and test lab servers where users or automation hold privileged local accounts. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.2%.

What to do: Upgrade VirtualBox 7.2.14 installations to the patched release published in Oracle's Critical Patch Update (check the Oracle Virtualization CPU advisory for the exact fixed 7.2.x version). Until patched, restrict high-privileged local logon access on VirtualBox hosts to trusted administrators and review what host resources VirtualBox can access. Note the scope change: treat exposed credentials or sensitive data readable by VirtualBox as potentially exposed to other products on the same infrastructure.

Affected
Oracle VM VirtualBox (Core)7.2.14 (the only supported version listed as affected)
Estimated exposure
largelikely hundreds of thousands of hosts on VirtualBox 7.2.x (no official install counts) — VirtualBox is one of the most widely deployed free desktop hypervisors with millions of cumulative installs among developers and test environments, but the flaw is limited to the 7.2.14 maintenance release of the 7.2 branch, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

Vendors
oracle
Products
vm virtualbox
Weakness
CWE-284
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

In the news

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI disclosed CVE-2026-71114, an out-of-bounds read in Oracle VirtualBox VirtioSCSI letting privileged local guest attackers disclose sensitive information.

The Zero Day Initiative published advisory ZDI-26-641 for an out-of-bounds read vulnerability in Oracle VirtualBox's VirtioSCSI component, assigned CVE-2026-71114 with a CVSS score of 6.1. The flaw allows local attackers to disclose sensitive information on affected installations. Exploitation requires an attacker to first obtain the ability to execute high-privileged code on the target guest system.