Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the VMSVGA device of Oracle VM VirtualBox, version 7.2.8. A locally authenticated attacker who can log on to the host system may exploit it to raise privileges within the virtual machine environment. Successful exploitation would allow total compromise of the virtual machine, resulting in loss of confidentiality, integrity, and availability for that VM as well as any additional products affected by scope changes. The weakness is rooted in improper privilege management.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox 7.2.8 is explicitly impacted. The advisory notes that attacks on this product may also threaten other Oracle products due to a scope change, although no other specific products are listed.

Risk and Exploitability

The CVSS base score of 7.5 denotes high severity, and the EPSS score of less than 1 % indicates the vulnerability is presently considered unlikely to be exploited in the wild. The attack vector is local and requires an already authenticated session on the host; therefore the risk is concentrated in environments where privileged users can launch virtual machines. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploitation at this time.

Generated by OpenCVE AI on June 17, 2026 at 18:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle VM VirtualBox release to eliminate the vulnerability.
  • If an update is not immediately available, remove or disable the VMSVGA graphics controller from virtual machines that do not require it.
  • Restrict local access to virtual machine host management and enforce least‑privilege for users who can launch VMs.
  • Enable host‑level monitoring and audit logging for virtual machine creation and configuration changes to detect attempts to abuse the VMSVGA device.

Generated by OpenCVE AI on June 17, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:13:06.004Z

Reserved: 2026-05-18T15:55:10.308Z

Link: CVE-2026-46873

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T01:00:15Z

Weaknesses

No weakness.