CVE-2026-21984
VirtualBox vulnerability analysis and mitigation

Overview

CVE-2026-21984 is an improper access control vulnerability in the Core component of Oracle VM VirtualBox that allows a high-privileged local attacker to fully compromise the hypervisor. Affected versions are 7.1.14 and 7.2.4. The vulnerability was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026. It carries a CVSS v3.1 base score of 7.5 (High), with a changed scope indicating that successful exploitation can impact systems beyond VirtualBox itself (Oracle CPU Jan 2026). The vulnerability was reported to Oracle by VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative (Oracle CPU Jan 2026).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) in the Core component of Oracle VM VirtualBox. Exploitation requires local access to the infrastructure where VirtualBox executes, high privileges, and involves high attack complexity — meaning specific conditions or race conditions must be met. The changed scope (S:C) in the CVSS vector indicates that a successful attack can extend beyond the VirtualBox process itself, potentially affecting the underlying host or other guest VMs. A proof-of-concept advisory was published by the Zero Day Initiative on February 13, 2026 (ZDI-26-099), providing additional technical context (ZDI Advisory, Oracle CPU Jan 2026).

Impact

Successful exploitation results in a complete takeover of Oracle VM VirtualBox, with high impacts to confidentiality, integrity, and availability. Due to the scope change, the attack can extend beyond the VirtualBox hypervisor to affect additional products or systems running on the same infrastructure, enabling potential lateral movement from a guest VM to the host or other guests. This makes the vulnerability particularly dangerous in multi-tenant or shared virtualization environments where isolation between workloads is critical (Oracle CPU Jan 2026).

Exploitation steps

  1. Gain high-privileged local access: The attacker must already possess high-privileged credentials (e.g., administrator or root) on the host system where Oracle VM VirtualBox 7.1.14 or 7.2.4 is running.
  2. Identify the vulnerable VirtualBox Core component: Confirm the installed VirtualBox version is 7.1.14 or 7.2.4 using version enumeration tools or by inspecting installed software.
  3. Leverage the improper access control flaw: Exploit the access control weakness in the VirtualBox Core component — likely involving manipulation of internal VirtualBox interfaces, device emulation, or inter-process communication under specific high-complexity conditions (exact technical details are limited to the ZDI advisory).
  4. Achieve hypervisor takeover: Successfully exploit the vulnerability to gain control of the VirtualBox hypervisor process, enabling arbitrary code execution at the hypervisor level.
  5. Pivot to additional systems: With scope change, leverage the compromised hypervisor to access other guest VMs, host resources, or connected infrastructure (ZDI Advisory, Oracle CPU Jan 2026).

Indicators of compromise

  • Process: Unexpected child processes spawned by the VirtualBox process (e.g., VBoxSVC, VBoxHeadless) executing system commands or spawning shells.
  • Logs: Unusual VirtualBox log entries in VBox.log or system event logs indicating abnormal Core component activity or access control errors; privilege escalation events in OS audit logs tied to VirtualBox service accounts.
  • File System: New or modified files in VirtualBox installation directories or VM configuration files (.vbox) altered without user action; unexpected kernel modules or drivers loaded on the host.
  • Network: Unexpected outbound network connections from the VirtualBox host process to external IPs, particularly following high-privileged user logon events.

Mitigation and workarounds

Oracle released patches for this vulnerability on January 20, 2026, as part of the January 2026 Critical Patch Update. Organizations should upgrade Oracle VM VirtualBox to versions beyond 7.1.14 and 7.2.4 by applying the available patches immediately. As interim mitigations, restrict local logon access to infrastructure hosting VirtualBox to only strictly necessary high-privileged users, and monitor VirtualBox systems for suspicious activity by privileged accounts. Oracle strongly recommends against relying on workarounds as a long-term solution (Oracle CPU Jan 2026).

Community reactions

The vulnerability was credited to VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative, who also published advisory ZDI-26-099 on February 13, 2026. The ZDI publication provided additional visibility into the vulnerability's technical nature. Social media activity was noted on platforms including Infosec.exchange and Bluesky shortly after disclosure, with standard community tracking of the Oracle CPU release (ZDI Advisory, Oracle CPU Jan 2026).

Additional resources


SourceThis report was generated using AI

Related VirtualBox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60159HIGH7.5
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoJul 21, 2026
CVE-2026-60158MEDIUM6.4
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60162MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60161MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60160LOW3.2
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management