VMSVGA Device Vulnerability in Oracle VM VirtualBox
CVE-2026-46873

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46873?

A vulnerability exists in the VMSVGA device component of Oracle VM VirtualBox, particularly in version 7.2.8. This flaw allows a high-privileged attacker with valid logon access to the infrastructure where Oracle VM VirtualBox operates to potentially compromise the system. While the primary targeting is Oracle VM VirtualBox, the repercussions of successful exploitation could extend, impacting other products and systems integrated with the virtualization environment. Organizations utilizing this version of Oracle VM VirtualBox are at risk of having their systems taken over, underscoring the necessity for immediate assessment and mitigation.

Affected Version(s)

Oracle VM VirtualBox 7.2.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.