Vulnerability in VMSVGA Device of Oracle VM VirtualBox by Oracle
CVE-2026-46815

3.2LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46815?

A vulnerability exists in the VMSVGA device component of Oracle VM VirtualBox, specifically in version 7.2.8. This issue allows an attacker with high privileges on the infrastructure running Oracle VM VirtualBox to potentially exploit the system. Successful exploitation could lead to unauthorized access to restricted data within the environment, impacting not only Oracle VM VirtualBox itself but also other related systems. Attackers may leverage this vulnerability to gain insights into sensitive information, emphasizing the importance of timely security measures.

Affected Version(s)

Oracle VM VirtualBox 7.2.8

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.