CVE-2026-21985 is a high-privilege vulnerability affecting Oracle VM VirtualBox versions 7.1.14 and 7.2.4. An attacker with logon access to the VirtualBox infrastructure can exploit this flaw to gain unauthorized access to critical or all VirtualBox-accessible data, potentially impacting other products. With a CVSS 3.1 Base Score of 6.0 (Medium), this vulnerability is easily exploitable with low attack complexity, primarily impacting confidentiality. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1.14CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:7.1.14:*:*:*:*:*:*:* | ||
7.2.4CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.