CVE-2026-60162
VirtualBox vulnerability analysis and mitigation

Overview

CVE-2026-60162 is a vulnerability in the Core component of Oracle VM VirtualBox affecting version 7.2.12, disclosed as part of Oracle's Critical Patch Update (CPU) for July 2026. It allows a high-privileged local attacker with logon access to the infrastructure to compromise VirtualBox, with a scope change indicating potential impact on additional products beyond VirtualBox itself. The vulnerability has a CVSS v3.1 base score of 6.1 (Medium) (Oracle Advisory). It was reported to Oracle by Xiaobye (xiaobye_tw) of DEVCORE Research Team working with TrendAI Zero Day Initiative (Oracle Advisory).

Technical details

The vulnerability resides in the Core component of Oracle VM VirtualBox and requires high privileges and local access to exploit, with high attack complexity (CWE classification not explicitly published by Oracle). The attack vector is local, meaning the attacker must have logon access to the system running VirtualBox, and no user interaction is required. The scope change (S:C) in the CVSS vector indicates that a successful exploit can affect resources beyond the VirtualBox process itself, potentially impacting the host or other guest VMs. No technical write-ups or public proof-of-concept code have been identified at this time (Oracle Advisory).

Impact

Successful exploitation can result in unauthorized access to critical data or complete access to all data accessible to Oracle VM VirtualBox, as well as a partial denial of service (partial DOS) of the VirtualBox service. The confidentiality impact is rated High and availability impact is Low, with no integrity impact. The scope change means exploitation could significantly affect additional products or components beyond VirtualBox itself, raising the risk of cross-VM or host-level data exposure (Oracle Advisory).

Mitigation and workarounds

Oracle has released a patch for this vulnerability as part of the July 2026 Critical Patch Update. Administrators should apply the CPU patch to Oracle VM VirtualBox 7.2.12 as soon as possible. As a temporary measure, Oracle recommends restricting local logon access to systems running VirtualBox to only trusted, high-privileged administrators. Oracle strongly advises against relying on workarounds as a long-term solution and recommends upgrading to a patched version (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related VirtualBox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60159HIGH7.5
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoJul 21, 2026
CVE-2026-60158MEDIUM6.4
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60162MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60161MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60160LOW3.2
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management