
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21985 is a data disclosure vulnerability in the Core component of Oracle VM VirtualBox, affecting versions 7.1.14 and 7.2.4. It was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update (CPU). The vulnerability allows a high-privileged local attacker to gain unauthorized access to critical data accessible by VirtualBox, with a scope change that may impact additional products. It carries a CVSS v3.1 base score of 6.0 (Medium) (Oracle CPU Jan 2026). The vulnerability was reported by Phudq of Viettel Cybersecurity working with Trend Micro Zero Day Initiative (Oracle CPU Jan 2026).
The vulnerability resides in the Core component of Oracle VM VirtualBox and is classified as a data/file disclosure issue (attack type: File / Data Disclosure). Exploitation requires local logon access to the infrastructure where VirtualBox executes, with high privileges, but no user interaction is needed. The attack complexity is low, and the scope is changed — meaning a successful exploit can affect resources beyond the VirtualBox process itself, potentially exposing data from the host or other guest VMs. A proof-of-concept advisory was published by the Zero Day Initiative (ZDI-26-100) on February 13, 2026 (ZDI Advisory, Oracle CPU Jan 2026).
Successful exploitation results in complete confidentiality loss — an attacker can gain unauthorized access to all data accessible by Oracle VM VirtualBox, including potentially sensitive guest VM data and host-accessible files. There is no integrity or availability impact. The scope change in the CVSS rating indicates that the impact can extend beyond the VirtualBox application itself to other products or resources on the same infrastructure (Oracle CPU Jan 2026).
VBoxSVC, VBoxHeadless, or VirtualBox) to files or memory regions outside normal guest VM boundaries.VBox.log) showing anomalous Core component interactions or errors consistent with exploitation attempts; OS-level audit logs recording high-privileged user activity against VirtualBox processes..vdi, .vmdk, .vhd) or VirtualBox configuration files by non-standard processes or users.Oracle has released patches for CVE-2026-21985 as part of the January 2026 Critical Patch Update; users should upgrade Oracle VM VirtualBox beyond versions 7.1.14 and 7.2.4 to the patched releases provided by Oracle. As a temporary workaround, restrict logon access to the infrastructure running VirtualBox to only necessary high-privileged personnel, reducing the attacker surface. Oracle strongly recommends applying CPU patches without delay and does not consider access restriction a long-term solution (Oracle CPU Jan 2026).
The vulnerability was reported to Oracle by Phudq of Viettel Cybersecurity in collaboration with Trend Micro's Zero Day Initiative, which subsequently published advisory ZDI-26-100 on February 13, 2026 (ZDI Advisory). No significant broader media coverage or notable community commentary specific to this CVE has been identified beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."