VMSVGA Device Vulnerability in Oracle VM VirtualBox
CVE-2026-46877

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46877?

An exploitable vulnerability exists in the VMSVGA device component of Oracle VM VirtualBox, impacting version 7.2.8. This flaw allows an attacker with high privileges and access to the infrastructure where Oracle VM VirtualBox operates to potentially compromise the system. Once exploited, the attacker could gain unauthorized access to critical data stored within the Oracle VM VirtualBox environment, resulting in possible exposure of sensitive information and complete access to all accessible data. It is essential for users of Oracle VM VirtualBox to implement necessary security measures to safeguard their environments against this vulnerability.

Affected Version(s)

Oracle VM VirtualBox 7.2.8

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.