CVE-2026-21989 is a high-severity vulnerability in Oracle VM VirtualBox versions 7.1.14 and 7.2.4, specifically within its Core component. A highly privileged attacker with infrastructure logon can compromise VirtualBox, potentially leading to unauthorized data creation, deletion, modification, or access, and partial denial of service. With a CVSS 3.1 score of 8.1, this vulnerability presents significant confidentiality, integrity, and availability impacts, and attacks may extend beyond VirtualBox to affect other products. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered notable community discussion, with 10 mentions indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1.14CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:7.1.14:*:*:*:*:*:*:* | ||
7.2.4CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.