ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 6 sources: “Zero Day Initiative publishes six Oracle VirtualBox advisories (ZDI-26-639 through ZDI-26-644) covering VMSVGA, VirtioSCSI, and IDisplay local guest flaws” — merged summary and timeline →

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

mediumVulnerabilityimportance 25CVE-2026-71114
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-71114, an out-of-bounds read in Oracle VirtualBox VirtioSCSI letting privileged local guest attackers disclose sensitive information.

The Zero Day Initiative published advisory ZDI-26-641 for an out-of-bounds read vulnerability in Oracle VirtualBox's VirtioSCSI component, assigned CVE-2026-71114 with a CVSS score of 6.1. The flaw allows local attackers to disclose sensitive information on affected installations. Exploitation requires an attacker to first obtain the ability to execute high-privileged code on the target guest system.

  • Out-of-bounds read in VirtualBox VirtioSCSI enables information disclosure, tracked as CVE-2026-71114.
  • Exploitation requires prior high-privileged code execution on the guest system.
  • ZDI assigned CVSS 6.1; no in-the-wild exploitation is mentioned.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-71114
Out-of-Bounds Read Information Disclosure in Oracle VM VirtualBox VirtioSCSI

CVE-2026-71114 is an information disclosure vulnerability in the Core component of Oracle VM VirtualBox; the ZDI advisory characterizes it as an out-of-bounds read in the VirtioSCSI component (Oracle classifies it under CWE-284, improper access control). It is triggered by an attacker who already has a high-privileged logon on the infrastructure where VirtualBox runs, requires no user interaction, and is rated easily exploitable. Successful attacks yield unauthorized access to critical data, potentially all data accessible to VirtualBox, and the scope change means the impact can extend to additional products beyond VirtualBox itself, though integrity and availability are unaffected. Any deployment running the affected 7.2.14 release of the 7.2 branch is exposed, including desktop hosts and test lab servers where users or automation hold privileged local accounts. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.2%.

Do: Upgrade VirtualBox 7.2.14 installations to the patched release published in Oracle's Critical Patch Update (check the Oracle Virtualization CPU advisory for the exact fixed 7.2.x version). Until patched, restrict high-privileged local logon access on VirtualBox hosts to trusted administrators and review what host resources VirtualBox can access. Note the scope change: treat exposed credentials or sensitive data readable by VirtualBox as potentially exposed to other products on the same infrastructure.

6.0<1%
  • Oracle VM VirtualBox (Core) 7.2.14 (the only supported version listed as affected)
largelikely hundreds of thousands of hosts on VirtualBox 7.2.x (no official install counts)
Full article

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.

This source does not provide full text. Read it at zerodayinitiative.com.