Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
Published: 2026-06-16
Score: 3.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the VMSVGA device of Oracle VM VirtualBox and permits an attacker who already has high‑privilege access on the host to read a subset of VirtualBox‑managed data. The flaw is exploitable locally, requires low effort, and has been classified as low severity (CVSS 3.2) with a low exploit probability (<1%) according to EPSS. The attack vector is inferred to be local, as the description notes a need for logon to the infrastructure where VirtualBox runs; no remote exploitation is described. Because the vulnerability’s scope can change, successful exploitation might gain unauthorized read access to other products running on the same host.

Affected Systems

Oracle’s VM VirtualBox version 7.2.8 is the only impacted release listed; the issue exists in the VMSVGA graphics device of that product. No other versions or components are indicated as affected.

Risk and Exploitability

With a CVSS score of 3.2 and EPSS below 1%, the risk is low for a single compromised host. However, because the flaw allows data exposure with high privileges, an attacker who can gain local logon could easily read sensitive VirtualBox information. The vulnerability is not listed in CISA’s KEV catalog, but administrators should consider prompt remediation given the potential breadth of data exposure and the possibility of scope escalation to other host‑resident products.

Generated by OpenCVE AI on June 17, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a non‑affected Oracle VM VirtualBox release issued after version 7.2.8 that removes the VMSVGA device flaw.
  • Enforce least‑privilege rules on the VirtualBox host, restricting high‑privilege local logons to trusted administrators only.
  • Enable host‑level auditing and monitor logs for unexpected read activity or configuration changes associated with VirtualBox data streams.

Generated by OpenCVE AI on June 17, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:27:11.472Z

Reserved: 2026-05-18T15:55:10.302Z

Link: CVE-2026-46816

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T01:15:16Z

Weaknesses

No weakness.