
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21984 is an improper access control vulnerability in the Core component of Oracle VM VirtualBox that allows a high-privileged local attacker to fully compromise the hypervisor. Affected versions are 7.1.14 and 7.2.4. The vulnerability was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026. It carries a CVSS v3.1 base score of 7.5 (High), with a changed scope indicating that successful exploitation can impact systems beyond VirtualBox itself (Oracle CPU Jan 2026). The vulnerability was reported to Oracle by VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative (Oracle CPU Jan 2026).
The vulnerability is classified as CWE-284 (Improper Access Control) in the Core component of Oracle VM VirtualBox. Exploitation requires local access to the infrastructure where VirtualBox executes, high privileges, and involves high attack complexity — meaning specific conditions or race conditions must be met. The changed scope (S:C) in the CVSS vector indicates that a successful attack can extend beyond the VirtualBox process itself, potentially affecting the underlying host or other guest VMs. A proof-of-concept advisory was published by the Zero Day Initiative on February 13, 2026 (ZDI-26-099), providing additional technical context (ZDI Advisory, Oracle CPU Jan 2026).
Successful exploitation results in a complete takeover of Oracle VM VirtualBox, with high impacts to confidentiality, integrity, and availability. Due to the scope change, the attack can extend beyond the VirtualBox hypervisor to affect additional products or systems running on the same infrastructure, enabling potential lateral movement from a guest VM to the host or other guests. This makes the vulnerability particularly dangerous in multi-tenant or shared virtualization environments where isolation between workloads is critical (Oracle CPU Jan 2026).
VBoxSVC, VBoxHeadless) executing system commands or spawning shells.VBox.log or system event logs indicating abnormal Core component activity or access control errors; privilege escalation events in OS audit logs tied to VirtualBox service accounts..vbox) altered without user action; unexpected kernel modules or drivers loaded on the host.Oracle released patches for this vulnerability on January 20, 2026, as part of the January 2026 Critical Patch Update. Organizations should upgrade Oracle VM VirtualBox to versions beyond 7.1.14 and 7.2.4 by applying the available patches immediately. As interim mitigations, restrict local logon access to infrastructure hosting VirtualBox to only strictly necessary high-privileged users, and monitor VirtualBox systems for suspicious activity by privileged accounts. Oracle strongly recommends against relying on workarounds as a long-term solution (Oracle CPU Jan 2026).
The vulnerability was credited to VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative, who also published advisory ZDI-26-099 on February 13, 2026. The ZDI publication provided additional visibility into the vulnerability's technical nature. Social media activity was noted on platforms including Infosec.exchange and Bluesky shortly after disclosure, with standard community tracking of the Oracle CPU release (ZDI Advisory, Oracle CPU Jan 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."