Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-35230
VirtualBox vulnerability analysis and mitigation

Overview

CVE-2026-35230 is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox version 7.2.6, classified as Improper Access Control (CWE-284). The flaw was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update. It was reported by VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory, Github Advisory).

Technical details

The vulnerability is rooted in improper access control (CWE-284) within the Core component of VirtualBox, with the ZDI advisory describing the underlying flaw as a "lack of proper locking" — indicative of a race condition in the SoundBlaster 16 emulation subsystem (ZDI Advisory, Systemtek). Exploitation requires a high-privileged attacker with local logon access to the host infrastructure running VirtualBox 7.2.6, and the attack complexity is rated High, meaning specific conditions must be met for successful exploitation. The scope is marked as "Changed," indicating that a successful attack can impact components beyond VirtualBox itself — potentially the host operating system or other guest VMs. No concrete reproduction steps or exploit code have been publicly released (ZDI Advisory).

Impact

Successful exploitation results in a full takeover of Oracle VM VirtualBox, with high impact to confidentiality, integrity, and availability. Because the scope changes upon exploitation, the attack may extend beyond the VirtualBox process to affect the underlying host system or co-located virtual machines, enabling potential lateral movement in virtualized environments. An attacker achieving this level of access could exfiltrate sensitive data from guest VMs, disrupt virtualization services, or persist on the host infrastructure (Oracle Advisory, Github Advisory).

Exploitability

No public proof-of-concept exploit code is currently available; the ZDI advisory page contains only vulnerability metadata and a reference to Oracle's patch, with no technical attack details or reproduction steps (ZDI Advisory). There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012% (0.028% per GitHub Advisory), placing it in a low exploitation probability tier. The vulnerability was reported by VMBreakers working with Trend Micro Zero Day Initiative, and no threat actor attribution has been made (Oracle Advisory, Github Advisory).

Mitigation and workarounds

Oracle has addressed this vulnerability in the April 2026 Critical Patch Update; users running VirtualBox 7.2.6 should apply the available patch immediately (Oracle Advisory). As a temporary risk reduction measure, Oracle recommends restricting local logon access to the infrastructure running VirtualBox to only authorized high-privileged users, and auditing all accounts with such access. Oracle explicitly states that blocking access or removing privileges are not long-term solutions and that patching is the only definitive remediation. Mageia Linux has also released an updated advisory for VirtualBox addressing this and related CVEs (Mageia Advisory).

Community reactions

The vulnerability was highlighted in the WaterISAC's weekly vulnerability prioritization report for April 30, 2026, indicating it was considered noteworthy for critical infrastructure defenders (WaterISAC). Kaspersky's threat intelligence portal catalogued the vulnerability as KLA90996, and RedPacket Security shared alerts on social media platforms including Mastodon. The Systemtek blog specifically identified the flaw as a SoundBlaster 16 race condition local privilege escalation, providing additional context beyond Oracle's terse advisory language (Systemtek). Overall community reaction has been measured, consistent with the vulnerability's high-privilege local-only exploitation requirement.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

virtualbox: 7.2.8-dfsg-1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

virtualbox

Unknown

devel

virtualbox

Unknown

focal (esm-apps)

virtualbox

Unknown

jammy

virtualbox

Unknown

jammy (esm-apps)

virtualbox

Unknown

noble

virtualbox

Unknown

noble (esm-apps)

virtualbox

Unknown

resolute

virtualbox

Unknown

SourceThis report was generated using AI

Related VirtualBox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-87285MEDIUM6
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoSep 15, 2026
CVE-2026-87283MEDIUM6
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoSep 15, 2026
CVE-2026-87282MEDIUM6
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoSep 15, 2026
CVE-2026-87284LOW3.2
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoSep 15, 2026
CVE-2026-87281LOW3.2
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management