CVE-2026-35249 is a local integrity vulnerability affecting Oracle VM VirtualBox version 7.2.6, specifically in the Core component. While the vulnerability resides in VirtualBox, successful exploitation may impact additional products due to scope change. The vulnerability presents a low severity risk with a CVSS 3.1 base score of 3.2. It requires local access and high-level privileges to exploit, making it accessible only to attackers with administrative or infrastructure access to the host system. The primary impact is limited to unauthorized data modification within VirtualBox accessible data, with no confidentiality or availability impacts. There is no evidence of active exploitation or public exploit code availability. The vulnerability is not included in CISA's Known Exploited Vulnerabilities (KEV) catalog and is not on any active hot list. Community attention remains minimal, with an extremely low EPSS score of 0.00011, indicating negligible real-world exploitation probability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.2.6CPE matchmatch criteria | cpe:2.3:a:oracle:vm_virtualbox:7.2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.