
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21955 is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox, classified as an Uncontrolled Resource Consumption flaw (CWE-400). It affects versions 7.1.14 and 7.2.4 and was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. The vulnerability carries a CVSS v3.1 base score of 8.2 (High), with a scope change indicating that successful exploitation can impact systems beyond VirtualBox itself (Oracle CPU Jan 2026). It was discovered and reported by VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative (Oracle CPU Jan 2026).
The vulnerability is rooted in uncontrolled resource consumption (CWE-400) within the VirtualBox Core component, specifically identified by ZDI as a use-after-free condition in the VMSVGA (VMware SVGA II) virtual graphics adapter implementation (ZDI Advisory, Systemtek). An attacker with high privileges (e.g., a guest VM administrator) and local logon access to the host infrastructure can trigger the flaw without any user interaction. The attack complexity is low, and the scope change means exploitation can affect the host system and other guest VMs beyond the initially compromised VirtualBox instance (Oracle CPU Jan 2026).
Successful exploitation allows a high-privileged local attacker to achieve complete takeover of Oracle VM VirtualBox, resulting in full compromise of confidentiality, integrity, and availability. Because the scope changes, the impact extends beyond the VirtualBox process itself — an attacker could potentially escape the guest VM environment and affect the host system and other co-hosted virtual machines. This creates significant risk in multi-tenant or shared virtualization environments where lateral movement to the host infrastructure is possible (Oracle CPU Jan 2026, ZDI Advisory).
VBoxSVC, VBoxHeadless) with elevated privileges or unusual parent-child relationships; VirtualBox process crashes or abnormal termination followed by restart.VBox.log) showing VMSVGA-related errors, memory access violations, or unexpected state transitions; host system logs indicating privilege escalation events tied to the VirtualBox service account.Oracle released patches for CVE-2026-21955 as part of the January 2026 Critical Patch Update (January 20, 2026); users should upgrade to a version beyond 7.1.14 or 7.2.4 as directed by Oracle's patch guidance (Oracle CPU Jan 2026). As a temporary workaround, restrict local access to systems running VirtualBox to trusted administrators only, and consider disabling the VMSVGA virtual graphics adapter in guest VM configurations where not required. Oracle strongly recommends applying the CPU patches without delay rather than relying on access restrictions as a long-term solution (Oracle CPU Jan 2026).
The vulnerability received moderate attention following the Oracle January 2026 CPU release, with coverage on security aggregators such as The Hacker Wire (Mastodon and Bluesky) and Red Packet Security shortly after disclosure. Greenbone Networks highlighted it in their January 2026 threat report as part of a broader analysis of the Oracle CPU (Greenbone Blog). The ZDI advisory published in February 2026 provided additional technical context, drawing further researcher attention to the VMSVGA use-after-free root cause (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."