Security Vulnerability Report
中文
CVE-2026-21963 CVSS 6.0 MEDIUM

CVE-2026-21963

Published: 2026-01-20 22:15:59
Last Modified: 2026-01-29 16:01:09

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

CVSS Details

CVSS Score
6.0
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Configurations (Affected Products)

cpe:2.3:a:oracle:vm_virtualbox:7.1.4:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:* - VULNERABLE
Oracle VM VirtualBox 7.1.14
Oracle VM VirtualBox 7.2.4

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
# CVE-2026-21963 PoC - Oracle VM VirtualBox Local Privilege Escalation # Note: This is a conceptual PoC for demonstration purposes # Actual exploitation requires specific conditions and environment import subprocess import sys def check_virtualbox_version(): """Check if vulnerable VirtualBox version is installed""" try: result = subprocess.run(['VBoxManage', '--version'], capture_output=True, text=True) version = result.stdout.strip() print(f"[*] Detected VirtualBox version: {version}") # Vulnerable versions: 7.1.14, 7.2.4 vulnerable_versions = ['7.1.14', '7.2.4'] if any(v in version for v in vulnerable_versions): print("[!] Vulnerable version detected!") return True else: print("[-] Version not in vulnerable list") return False except Exception as e: print(f"[-] Error checking version: {e}") return False def exploit_cve_2026_21963(): """ Conceptual exploitation steps for CVE-2026-21963 Actual exploitation requires specific vulnerable component access """ print("[*] CVE-2026-21963 Exploitation Attempt") print("[*] Requirements: High privilege access to VirtualBox host system") if not check_virtualbox_version(): print("[-] Target not vulnerable") return False print("[*] Attempting to access protected VirtualBox core components...") # Placeholder for actual exploitation logic # Real exploitation would target specific Core component vulnerability print("[!] This is a proof-of-concept. Actual exploitation may vary.") return True if __name__ == "__main__": print("CVE-2026-21963 PoC - Oracle VM VirtualBox Vulnerability") print("=" * 60) exploit_cve_2026_21963()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-21963", "sourceIdentifier": "[email protected]", "published": "2026-01-20T22:15:59.230", "lastModified": "2026-01-29T16:01:09.270", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N)."}, {"lang": "es", "value": "Vulnerabilidad en el producto Oracle VM VirtualBox de Oracle Virtualization (componente: Core). Versiones soportadas que están afectadas son 7.1.14 y 7.2.4. Vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con inicio de sesión en la infraestructura donde se ejecuta Oracle VM VirtualBox comprometer Oracle VM VirtualBox. Aunque la vulnerabilidad está en Oracle VM VirtualBox, los ataques pueden impactar significativamente productos adicionales (cambio de alcance). Ataques exitosos de esta vulnerabilidad pueden resultar en acceso no autorizado a datos críticos o acceso completo a todos los datos accesibles por Oracle VM VirtualBox. CVSS 3.1 Puntuación Base 6.0 (Impactos en la confidencialidad). Vector CVSS: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N)."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N", "baseScore": 6.0, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE"}, "exploitabilityScore": 1.5, "impactScore": 4.0}]}, "weaknesses": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-269"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:oracle:vm_virtualbox:7.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "39934CFB-352A-47C3-8F1B-96568708D325"}, {"vulnerable": true, "criteria": "cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:*", "matchCriteriaId": "44ABFABE-8FFC-48CF-B627-4241CAD563B6"}]}]}], "references": [{"url": "https://www.oracle.com/security-alerts/cpujan2026.html", "source": "[email protected]", "tags": ["Vendor Advisory"]}]}}