Vulnerability in VMSVGA Device of Oracle VM VirtualBox by Oracle
CVE-2026-46977

3.2LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46977?

A vulnerability exists in the VMSVGA device of Oracle VM VirtualBox, specifically affecting version 7.2.8. This flaw can be exploited by a highly privileged attacker who has logon access to the environment where Oracle VM VirtualBox runs. The exploitation may lead to unauthorized read access to specific data within Oracle VM VirtualBox, potentially impacting other products in the system. It is essential for organizations utilizing this virtualization technology to mitigate risks associated with this vulnerability.

Affected Version(s)

Oracle VM VirtualBox 7.2.8

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.