Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who has local administrative or privileged access on a host running Oracle VM VirtualBox 7.2.8 can exploit a flaw in the Core component to take full control of the VirtualBox process, leading to loss of confidentiality, integrity, and availability for the virtual machine environment and potentially other connected products. The vulnerability is classified as a local privilege escalation that can compromise the entire virtualization stack.

Affected Systems

Oracle VirtualBox version 7.2.8 is affected. No other Oracle Virtualization products or third‑party components are explicitly listed as vulnerable, but the impact scope may extend to other products that rely on VirtualBox.

Risk and Exploitability

The CVSS 3.1 base score is 7.5, indicating high severity with full impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. However, because the exploit requires privileged local access, it can be highly destructive if leveraged by a malicious actor who has already gained administrative or equivalent rights on the host system. The combination of high critical impact and low external exploitation probability underscores the need for vigilant monitoring and timely patching once a fix becomes available.

Generated by OpenCVE AI on June 17, 2026 at 18:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's official patch for VirtualBox 7.2.8 as soon as it is released
  • Enforce least privilege for users and services that run Oracle VirtualBox, ensuring no unnecessary administrative rights
  • Isolate VirtualBox deployments from critical infrastructure and monitoring systems to contain potential lateral movement

Generated by OpenCVE AI on June 17, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:33:12.810Z

Reserved: 2026-05-18T15:55:10.314Z

Link: CVE-2026-46974

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:00:16Z

Weaknesses

No weakness.