CVE-2026-21955
VirtualBox vulnerability analysis and mitigation

Overview

CVE-2026-21955 is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox, classified as an Uncontrolled Resource Consumption flaw (CWE-400). It affects versions 7.1.14 and 7.2.4 and was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. The vulnerability carries a CVSS v3.1 base score of 8.2 (High), with a scope change indicating that successful exploitation can impact systems beyond VirtualBox itself (Oracle CPU Jan 2026). It was discovered and reported by VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative (Oracle CPU Jan 2026).

Technical details

The vulnerability is rooted in uncontrolled resource consumption (CWE-400) within the VirtualBox Core component, specifically identified by ZDI as a use-after-free condition in the VMSVGA (VMware SVGA II) virtual graphics adapter implementation (ZDI Advisory, Systemtek). An attacker with high privileges (e.g., a guest VM administrator) and local logon access to the host infrastructure can trigger the flaw without any user interaction. The attack complexity is low, and the scope change means exploitation can affect the host system and other guest VMs beyond the initially compromised VirtualBox instance (Oracle CPU Jan 2026).

Impact

Successful exploitation allows a high-privileged local attacker to achieve complete takeover of Oracle VM VirtualBox, resulting in full compromise of confidentiality, integrity, and availability. Because the scope changes, the impact extends beyond the VirtualBox process itself — an attacker could potentially escape the guest VM environment and affect the host system and other co-hosted virtual machines. This creates significant risk in multi-tenant or shared virtualization environments where lateral movement to the host infrastructure is possible (Oracle CPU Jan 2026, ZDI Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target host running Oracle VM VirtualBox versions 7.1.14 or 7.2.4 with the VMSVGA virtual graphics adapter enabled. Confirm local or guest-level privileged access to the system.
  2. Gain initial access: Obtain high-privileged access within a guest VM or directly on the host system running VirtualBox (e.g., as a guest OS administrator).
  3. Trigger use-after-free: Craft and send specially crafted VMSVGA graphics commands or operations that cause a use-after-free condition in the VirtualBox Core component, leading to uncontrolled resource consumption.
  4. Exploit memory corruption: Leverage the use-after-free condition to corrupt memory in the VirtualBox process, enabling arbitrary code execution in the context of the hypervisor.
  5. Achieve hypervisor takeover: Escalate privileges to gain full control of the VirtualBox hypervisor, potentially enabling guest-to-host escape, access to other guest VMs, and compromise of the underlying host infrastructure (ZDI Advisory, Systemtek).

Indicators of compromise

  • Process: Unexpected child processes spawned by the VirtualBox process (e.g., VBoxSVC, VBoxHeadless) with elevated privileges or unusual parent-child relationships; VirtualBox process crashes or abnormal termination followed by restart.
  • Logs: VirtualBox log files (VBox.log) showing VMSVGA-related errors, memory access violations, or unexpected state transitions; host system logs indicating privilege escalation events tied to the VirtualBox service account.
  • File System: Unexpected files written to the VirtualBox installation directory or host system directories by the VirtualBox process; new or modified configuration files in VirtualBox VM directories.
  • Network: Unusual outbound network connections from the VirtualBox host process to external IPs, potentially indicating post-exploitation activity such as reverse shell or data exfiltration (ZDI Advisory).

Mitigation and workarounds

Oracle released patches for CVE-2026-21955 as part of the January 2026 Critical Patch Update (January 20, 2026); users should upgrade to a version beyond 7.1.14 or 7.2.4 as directed by Oracle's patch guidance (Oracle CPU Jan 2026). As a temporary workaround, restrict local access to systems running VirtualBox to trusted administrators only, and consider disabling the VMSVGA virtual graphics adapter in guest VM configurations where not required. Oracle strongly recommends applying the CPU patches without delay rather than relying on access restrictions as a long-term solution (Oracle CPU Jan 2026).

Community reactions

The vulnerability received moderate attention following the Oracle January 2026 CPU release, with coverage on security aggregators such as The Hacker Wire (Mastodon and Bluesky) and Red Packet Security shortly after disclosure. Greenbone Networks highlighted it in their January 2026 threat report as part of a broader analysis of the Oracle CPU (Greenbone Blog). The ZDI advisory published in February 2026 provided additional technical context, drawing further researcher attention to the VMSVGA use-after-free root cause (ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Related VirtualBox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60159HIGH7.5
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoJul 21, 2026
CVE-2026-60158MEDIUM6.4
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60162MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60161MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60160LOW3.2
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management