
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21963 is an Improper Privilege Management vulnerability in the Core component of Oracle VM VirtualBox, affecting versions 7.1.14 and 7.2.4. It was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. The vulnerability allows a high-privileged local attacker to compromise VirtualBox and gain unauthorized read access to sensitive data, with a scope change that may impact additional products beyond VirtualBox itself. It carries a CVSS v3.1 base score of 6.0 (Medium) (Oracle CPU Jan 2026).
The vulnerability is classified as CWE-269 (Improper Privilege Management) and resides in the Core component of Oracle VM VirtualBox. It is a local attack vector (AV:L) requiring high privileges (PR:H) and no user interaction, with low attack complexity. The flaw enables a privileged attacker with logon access to the host infrastructure to abuse elevated control mechanisms — mapped to CAPEC-122 (Privilege Abuse) and CAPEC-233 (Privilege Escalation) — to read data outside the intended scope of the VirtualBox process, including potentially sensitive virtual machine and hypervisor data. A proof-of-concept advisory was published by Trend Micro Zero Day Initiative on February 13, 2026, and the vulnerability was reported by Viettel Cyber Security working with Trend Micro ZDI (Oracle CPU Jan 2026, ZDI Advisory).
Successful exploitation results in unauthorized access to critical data or complete access to all data accessible by Oracle VM VirtualBox, constituting a high confidentiality impact. There is no integrity or availability impact. Because the scope changes upon successful exploitation, sensitive information from guest virtual machines and the hypervisor itself may be exposed to the attacker, potentially enabling lateral movement within a virtualized infrastructure (Oracle CPU Jan 2026).
dd, strings, custom tools) spawned in the context of a VirtualBox session by a privileged user..vdi, .vmdk, or VirtualBox snapshot files by accounts not normally associated with VM management.Oracle has released patches for affected versions (7.1.14 and 7.2.4) as part of the January 2026 Critical Patch Update, published January 20, 2026. Organizations should apply the CPU patches immediately by following Oracle's patch availability documentation. As interim measures, restrict high-privilege logon access to hosts running VirtualBox to only authorized administrators, and monitor and audit privileged user activities on affected systems. Oracle strongly recommends against relying on workarounds as a long-term solution (Oracle CPU Jan 2026).
The vulnerability was reported to Oracle by Viettel Cyber Security working with Trend Micro Zero Day Initiative, which subsequently published advisory ZDI-26-101 on February 13, 2026. No significant broader media coverage or notable community commentary has been identified beyond the standard advisory publications (Oracle CPU Jan 2026, ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."