Vulnerability in Oracle VM VirtualBox 7.2.8 by Oracle Virtualization
CVE-2026-46874

3.2LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46874?

A vulnerability exists in Oracle VM VirtualBox version 7.2.8 which could allow a highly privileged attacker with access to the infrastructure where Oracle VM VirtualBox operates to compromise it. This vulnerability facilitates unauthorized read access to the data within Oracle VM VirtualBox, which may have broader implications for any systems leveraging its access. The risk extends beyond just Oracle VM VirtualBox, potentially impacting other integrated products.

Affected Version(s)

Oracle VM VirtualBox 7.2.8

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.