
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21982 is an Improper Access Control vulnerability (CWE-284) in the Core component of Oracle VM VirtualBox, affecting versions 7.1.14 and 7.2.4. It was disclosed and patched as part of Oracle's January 2026 Critical Patch Update (CPU), released on January 20, 2026. The vulnerability allows an unauthenticated attacker with access to the physical communication segment attached to the hardware running VirtualBox to compromise the hypervisor and achieve full system takeover. The CVSS v3.1 base score is 7.5 (High) per Oracle's advisory, though Feedly's analysis notes a score of 6.4 (Medium) using a physical attack vector variant (Oracle CPU Jan 2026). The vulnerability was reported to Oracle by Ao Wang of Southeast University (Oracle CPU Jan 2026).
The vulnerability is classified as CWE-284 (Improper Access Control) in the Core component of Oracle VM VirtualBox. Exploitation requires an attacker to have access to the physical communication segment (local network segment) attached to the hardware where VirtualBox executes — meaning the attacker must be on the same physical or adjacent network segment, not necessarily with physical hands-on access to the machine. The attack complexity is rated High, no privileges are required, and no user interaction is needed. Successful exploitation can result in complete takeover of the VirtualBox hypervisor, impacting all guest virtual machines running on it. No public technical write-ups or proof-of-concept code have been identified at this time (Oracle CPU Jan 2026).
Successful exploitation results in a full takeover of Oracle VM VirtualBox, with high impacts to confidentiality, integrity, and availability. An attacker achieving hypervisor-level compromise gains control over all guest virtual machines running on the affected host, enabling arbitrary code execution with hypervisor privileges, data exfiltration from guest VMs, and potential lateral movement across virtualized environments. The scope is limited to the affected VirtualBox instance (Scope: Unchanged), but the breadth of impact across all hosted VMs makes this a significant risk in multi-tenant or server virtualization scenarios (Oracle CPU Jan 2026).
Oracle has released patches for the affected versions (7.1.14 and 7.2.4) as part of the January 2026 Critical Patch Update. Organizations should apply the CPU patches immediately by upgrading to the patched VirtualBox releases provided by Oracle. As interim mitigations, restrict physical and network access to the communication segments connected to VirtualBox hosts, implement network segmentation to limit which systems can communicate with VirtualBox hosts, and apply the principle of least privilege to network access controls. Oracle strongly recommends against relying on network-blocking workarounds as a long-term solution (Oracle CPU Jan 2026).
The vulnerability received routine coverage from security aggregators and automated alert services such as RedPacket Security and CVE monitoring feeds. No notable independent researcher commentary or significant media coverage beyond standard CPU advisory reporting has been identified. Community sentiment reflects the typical response to Oracle CPU disclosures — awareness of the patch with limited urgency given the High attack complexity and adjacency requirement.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."