Denial of Service Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-46768

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46768?

A security vulnerability exists in Oracle VM VirtualBox's VMSVGA device, specifically in version 7.2.8. This vulnerability may be exploited by a privileged attacker who has logged into the environment where Oracle VM VirtualBox is deployed. Successful exploitation can lead to unauthorized actions that hamper the availability of the application, potentially causing repeated hangs or crashes. This raises significant risks of Denial of Service attacks affecting overall system performance and reliability across associated products.

Affected Version(s)

Oracle VM VirtualBox 7.2.8

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.