
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21988 is a privilege escalation vulnerability in the Core component of Oracle VM VirtualBox, affecting versions 7.1.14 and 7.2.4. It was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. The vulnerability allows a high-privileged local attacker to fully compromise the VirtualBox instance, with a scope change indicating potential impact on additional products beyond VirtualBox itself. It carries a CVSS v3.1 base score of 8.2 (High) (Oracle CPU Jan 2026).
The vulnerability resides in the Core component of Oracle VM VirtualBox and is classified as an easily exploitable local privilege escalation issue. An attacker with high privileges and local logon access to the infrastructure where VirtualBox executes can leverage this flaw to achieve a complete takeover of the virtualization platform. The scope change (S:C) in the CVSS vector indicates that a successful exploit can affect resources beyond the vulnerable component itself, potentially impacting guest or host systems. The vulnerability was reported by Zhenghao Li of ISCAS (Oracle CPU Jan 2026). No specific CWE classification or detailed technical write-up has been publicly disclosed.
Successful exploitation results in a complete takeover of Oracle VM VirtualBox, with high impacts to confidentiality, integrity, and availability. Because the vulnerability involves a scope change, the compromise may extend beyond the VirtualBox process itself to affect the underlying host system or co-located virtual machines, enabling potential lateral movement within virtualized infrastructure. Sensitive data processed within VirtualBox environments could be exposed or manipulated (Oracle CPU Jan 2026).
Oracle has released patches for CVE-2026-21988 as part of the January 2026 Critical Patch Update. Administrators should upgrade Oracle VM VirtualBox from the affected versions (7.1.14 and 7.2.4) to the patched versions provided in the CPU. As an interim measure, restrict logon access to the infrastructure running VirtualBox to only authorized, trusted users, and monitor for unauthorized privilege escalation activity. Oracle strongly recommends applying Critical Patch Update patches without delay (Oracle CPU Jan 2026).
The vulnerability received routine coverage from automated vulnerability tracking services and security feeds following Oracle's January 2026 CPU release. No notable independent researcher commentary or significant media coverage specific to CVE-2026-21988 has been identified beyond standard advisory republication (Oracle CPU Jan 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."