Junglewise Threat Intelligence

CVE-2026-46768: Oracle VM VirtualBox denial of service in VMSVGA device

CVE-2026-46768 · Severity: medium · CVSS 6 · Published 2026-06-17

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

A vulnerability in Oracle VM VirtualBox's VMSVGA graphics device allows a high-privileged user on the host system to crash the virtualization software. This can lead to a complete denial of service, causing virtual machines to hang or restart unexpectedly. While the flaw exists within VirtualBox, the impact can extend to other integrated products or the stability of the host infrastructure.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the VMSVGA device component of Oracle VM VirtualBox. It is exploitable by a local attacker with high privileges on the infrastructure where VirtualBox is running. The exploit results in a 'scope change' (S:C), meaning the impact can propagate beyond the VirtualBox application itself. Successful exploitation allows the attacker to trigger a frequently repeatable crash or a permanent hang of the service, resulting in a complete loss of availability. The vulnerability is confirmed to affect version 7.2.8.

Affected products

  • Oracle VM VirtualBox 7.2.8

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD record published

References

Related threats