CVE-2026-21985
VirtualBox vulnerability analysis and mitigation

Overview

CVE-2026-21985 is a data disclosure vulnerability in the Core component of Oracle VM VirtualBox, affecting versions 7.1.14 and 7.2.4. It was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update (CPU). The vulnerability allows a high-privileged local attacker to gain unauthorized access to critical data accessible by VirtualBox, with a scope change that may impact additional products. It carries a CVSS v3.1 base score of 6.0 (Medium) (Oracle CPU Jan 2026). The vulnerability was reported by Phudq of Viettel Cybersecurity working with Trend Micro Zero Day Initiative (Oracle CPU Jan 2026).

Technical details

The vulnerability resides in the Core component of Oracle VM VirtualBox and is classified as a data/file disclosure issue (attack type: File / Data Disclosure). Exploitation requires local logon access to the infrastructure where VirtualBox executes, with high privileges, but no user interaction is needed. The attack complexity is low, and the scope is changed — meaning a successful exploit can affect resources beyond the VirtualBox process itself, potentially exposing data from the host or other guest VMs. A proof-of-concept advisory was published by the Zero Day Initiative (ZDI-26-100) on February 13, 2026 (ZDI Advisory, Oracle CPU Jan 2026).

Impact

Successful exploitation results in complete confidentiality loss — an attacker can gain unauthorized access to all data accessible by Oracle VM VirtualBox, including potentially sensitive guest VM data and host-accessible files. There is no integrity or availability impact. The scope change in the CVSS rating indicates that the impact can extend beyond the VirtualBox application itself to other products or resources on the same infrastructure (Oracle CPU Jan 2026).

Exploitation steps

  1. Gain high-privileged local access: The attacker must already have administrative or high-privileged credentials on the host system where Oracle VM VirtualBox 7.1.14 or 7.2.4 is installed.
  2. Identify the vulnerable VirtualBox Core component: Confirm the installed VirtualBox version is 7.1.14 or 7.2.4 using version enumeration tools or by checking installed software.
  3. Leverage the Core vulnerability: Using the technique detailed in ZDI-26-100, interact with the VirtualBox Core component in a manner that triggers the data disclosure flaw — likely through a crafted API call, shared folder access, or guest-host communication channel.
  4. Access disclosed data: Retrieve sensitive data exposed by the vulnerability, which may include guest VM memory, disk contents, or other data accessible to the VirtualBox process, potentially spanning multiple VMs or host resources due to the scope change (ZDI Advisory, Oracle CPU Jan 2026).

Indicators of compromise

  • Process: Unusual or unexpected access patterns by the VirtualBox process (VBoxSVC, VBoxHeadless, or VirtualBox) to files or memory regions outside normal guest VM boundaries.
  • Logs: VirtualBox log files (VBox.log) showing anomalous Core component interactions or errors consistent with exploitation attempts; OS-level audit logs recording high-privileged user activity against VirtualBox processes.
  • File System: Unexpected file reads or copies of guest VM disk images (.vdi, .vmdk, .vhd) or VirtualBox configuration files by non-standard processes or users.
  • Network: Outbound data transfers from the VirtualBox host to unknown external destinations following local access events, potentially indicating exfiltration of disclosed data.

Mitigation and workarounds

Oracle has released patches for CVE-2026-21985 as part of the January 2026 Critical Patch Update; users should upgrade Oracle VM VirtualBox beyond versions 7.1.14 and 7.2.4 to the patched releases provided by Oracle. As a temporary workaround, restrict logon access to the infrastructure running VirtualBox to only necessary high-privileged personnel, reducing the attacker surface. Oracle strongly recommends applying CPU patches without delay and does not consider access restriction a long-term solution (Oracle CPU Jan 2026).

Community reactions

The vulnerability was reported to Oracle by Phudq of Viettel Cybersecurity in collaboration with Trend Micro's Zero Day Initiative, which subsequently published advisory ZDI-26-100 on February 13, 2026 (ZDI Advisory). No significant broader media coverage or notable community commentary specific to this CVE has been identified beyond standard vulnerability tracking and aggregation sites.

Additional resources


SourceThis report was generated using AI

Related VirtualBox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60159HIGH7.5
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoJul 21, 2026
CVE-2026-60158MEDIUM6.4
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60162MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60161MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60160LOW3.2
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management