CVE-2026-35230General(oracle / vm_virtualbox)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm_virtualbox

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
vm_virtualbox

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-26: 1Mentions · 2026-04-30: 1Technical Details · 2026-04-30: 104-2604-30
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-301
Disclosure1
Full discourse2 posts
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Oracle VirtualBox SoundBlaster 16 Race Condition Local Privilege Escalation Vulnerability (CVE-2026-35230) #CVE202635230 #CyberSecurity #LocalPrivilegeEscalation #OracleVirtualBox https://www.systemtek.co.uk/?p=50856 https://t.co/fk7DwzqXzc

    Post summary

    The tweet announces the identification of CVE-2026-35230, a race‑condition based LPE in Oracle VirtualBox’s SoundBlaster 16 component, but provides no PoC, exploit, or patch details.

    0000028
    1.8K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35230 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit … https://www.cve.org/CVERecord?id=CVE-2026-35230

    Post summary

    A brief statement noting CVE‑2026‑35230 affects Oracle VM VirtualBox 7.2.6, described as difficult to exploit, with only a link to the CVE record.

    0000096
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclevm_virtualbox7.2.6--

Explore more