
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60161 is a vulnerability in the Core component of Oracle VM VirtualBox affecting version 7.2.12, disclosed as part of Oracle's Critical Patch Update (CPU) for July 2026. The vulnerability allows an unauthenticated local attacker — with required human interaction from another user — to cause a complete denial of service (hang or crash) of VirtualBox and perform limited unauthorized data modification. It carries a CVSS v3.1 base score of 6.1 (Medium) (Oracle Advisory). The vulnerability was reported to Oracle by Giovanni Vignone, Paolo Gentry, Robert van Eijk, and Shubham Antil of Octane Security (Oracle Advisory).
The vulnerability resides in the Core component of Oracle VM VirtualBox 7.2.12 and is classified as easily exploitable under low attack complexity conditions. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction (UI:R) from a person other than the attacker, suggesting a social engineering or malicious file/input scenario. The scope is unchanged, meaning the impact is confined to VirtualBox itself. No specific CWE classification has been publicly disclosed, and Oracle has not released detailed technical write-ups or proof-of-concept code (Oracle Advisory).
Successful exploitation results in a complete denial of service — the attacker can cause Oracle VM VirtualBox to hang or crash repeatedly — as well as limited unauthorized update, insert, or delete access to some VirtualBox-accessible data. There is no confidentiality impact (C:N), meaning sensitive data exposure is not a direct consequence. The impact is scoped to the VirtualBox instance itself and does not extend to the underlying host OS or other virtualized guests based on the unchanged scope rating (Oracle Advisory).
Oracle has released a patch for this vulnerability as part of the July 2026 Critical Patch Update. Users running Oracle VM VirtualBox 7.2.12 should apply the available security patch immediately by following the guidance in the Oracle CPU documentation (Oracle Advisory). As a temporary measure, Oracle recommends restricting local access to systems running the affected VirtualBox version to trusted users only and implementing access controls to limit interaction with VirtualBox instances. Monitoring for unexpected VirtualBox process crashes or hangs can serve as an early indicator of exploitation attempts.
The vulnerability was credited to researchers Giovanni Vignone, Paolo Gentry, Robert van Eijk, and Shubham Antil of Octane Security, indicating coordinated disclosure with Oracle (Oracle Advisory). No significant public commentary, media coverage, or social media discussion has been observed beyond the standard CPU release coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."