CVE-2026-60161
VirtualBox vulnerability analysis and mitigation

Overview

CVE-2026-60161 is a vulnerability in the Core component of Oracle VM VirtualBox affecting version 7.2.12, disclosed as part of Oracle's Critical Patch Update (CPU) for July 2026. The vulnerability allows an unauthenticated local attacker — with required human interaction from another user — to cause a complete denial of service (hang or crash) of VirtualBox and perform limited unauthorized data modification. It carries a CVSS v3.1 base score of 6.1 (Medium) (Oracle Advisory). The vulnerability was reported to Oracle by Giovanni Vignone, Paolo Gentry, Robert van Eijk, and Shubham Antil of Octane Security (Oracle Advisory).

Technical details

The vulnerability resides in the Core component of Oracle VM VirtualBox 7.2.12 and is classified as easily exploitable under low attack complexity conditions. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction (UI:R) from a person other than the attacker, suggesting a social engineering or malicious file/input scenario. The scope is unchanged, meaning the impact is confined to VirtualBox itself. No specific CWE classification has been publicly disclosed, and Oracle has not released detailed technical write-ups or proof-of-concept code (Oracle Advisory).

Impact

Successful exploitation results in a complete denial of service — the attacker can cause Oracle VM VirtualBox to hang or crash repeatedly — as well as limited unauthorized update, insert, or delete access to some VirtualBox-accessible data. There is no confidentiality impact (C:N), meaning sensitive data exposure is not a direct consequence. The impact is scoped to the VirtualBox instance itself and does not extend to the underlying host OS or other virtualized guests based on the unchanged scope rating (Oracle Advisory).

Mitigation and workarounds

Oracle has released a patch for this vulnerability as part of the July 2026 Critical Patch Update. Users running Oracle VM VirtualBox 7.2.12 should apply the available security patch immediately by following the guidance in the Oracle CPU documentation (Oracle Advisory). As a temporary measure, Oracle recommends restricting local access to systems running the affected VirtualBox version to trusted users only and implementing access controls to limit interaction with VirtualBox instances. Monitoring for unexpected VirtualBox process crashes or hangs can serve as an early indicator of exploitation attempts.

Community reactions

The vulnerability was credited to researchers Giovanni Vignone, Paolo Gentry, Robert van Eijk, and Shubham Antil of Octane Security, indicating coordinated disclosure with Oracle (Oracle Advisory). No significant public commentary, media coverage, or social media discussion has been observed beyond the standard CPU release coverage.

Additional resources


SourceThis report was generated using AI

Related VirtualBox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60159HIGH7.5
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoJul 21, 2026
CVE-2026-60158MEDIUM6.4
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60162MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60161MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60160LOW3.2
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management