Vulnerability in Oracle VM VirtualBox Affects Multiple Environments
CVE-2026-46816

3.2LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46816?

A vulnerability exists in Oracle VM VirtualBox, specifically within the VMSVGA device, allowing a privileged attacker with logon access to exploit the system. This weakness could enable unauthorized read access to sensitive data managed by Oracle VM VirtualBox. Successful exploitation may extend its impact to other products, thereby increasing the risk to the overall infrastructure.

Affected Version(s)

Oracle VM VirtualBox 7.2.8

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.