
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35230 is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox version 7.2.6, classified as Improper Access Control (CWE-284). The flaw was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update. It was reported by VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory, Github Advisory).
The vulnerability is rooted in improper access control (CWE-284) within the Core component of VirtualBox, with the ZDI advisory describing the underlying flaw as a "lack of proper locking" — indicative of a race condition in the SoundBlaster 16 emulation subsystem (ZDI Advisory, Systemtek). Exploitation requires a high-privileged attacker with local logon access to the host infrastructure running VirtualBox 7.2.6, and the attack complexity is rated High, meaning specific conditions must be met for successful exploitation. The scope is marked as "Changed," indicating that a successful attack can impact components beyond VirtualBox itself — potentially the host operating system or other guest VMs. No concrete reproduction steps or exploit code have been publicly released (ZDI Advisory).
Successful exploitation results in a full takeover of Oracle VM VirtualBox, with high impact to confidentiality, integrity, and availability. Because the scope changes upon exploitation, the attack may extend beyond the VirtualBox process to affect the underlying host system or co-located virtual machines, enabling potential lateral movement in virtualized environments. An attacker achieving this level of access could exfiltrate sensitive data from guest VMs, disrupt virtualization services, or persist on the host infrastructure (Oracle Advisory, Github Advisory).
No public proof-of-concept exploit code is currently available; the ZDI advisory page contains only vulnerability metadata and a reference to Oracle's patch, with no technical attack details or reproduction steps (ZDI Advisory). There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012% (0.028% per GitHub Advisory), placing it in a low exploitation probability tier. The vulnerability was reported by VMBreakers working with Trend Micro Zero Day Initiative, and no threat actor attribution has been made (Oracle Advisory, Github Advisory).
Oracle has addressed this vulnerability in the April 2026 Critical Patch Update; users running VirtualBox 7.2.6 should apply the available patch immediately (Oracle Advisory). As a temporary risk reduction measure, Oracle recommends restricting local logon access to the infrastructure running VirtualBox to only authorized high-privileged users, and auditing all accounts with such access. Oracle explicitly states that blocking access or removing privileges are not long-term solutions and that patching is the only definitive remediation. Mageia Linux has also released an updated advisory for VirtualBox addressing this and related CVEs (Mageia Advisory).
The vulnerability was highlighted in the WaterISAC's weekly vulnerability prioritization report for April 30, 2026, indicating it was considered noteworthy for critical infrastructure defenders (WaterISAC). Kaspersky's threat intelligence portal catalogued the vulnerability as KLA90996, and RedPacket Security shared alerts on social media platforms including Mastodon. The Systemtek blog specifically identified the flaw as a SoundBlaster 16 race condition local privilege escalation, providing additional context beyond Oracle's terse advisory language (Systemtek). Overall community reaction has been measured, consistent with the vulnerability's high-privilege local-only exploitation requirement.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."