Junglewise Threat Intelligence

CVE-2026-46816: Oracle VM VirtualBox information disclosure in VMSVGA device

CVE-2026-46816 · Severity: low · CVSS 3.2 · Published 2026-06-17

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle VM VirtualBox, a popular tool used to run multiple operating systems on a single computer. A highly privileged user on the host system could exploit this flaw to gain unauthorized access to certain data within the VirtualBox environment. While the direct impact is limited to reading specific data, the breach could potentially affect other software running on the same infrastructure.

Technical details

An information disclosure vulnerability (CWE-200) exists in the VMSVGA device component of Oracle VM VirtualBox version 7.2.8. The flaw is categorized as easily exploitable but requires the attacker to have high privileges and local logon access to the infrastructure where VirtualBox is executing. Successful exploitation results in a scope change (S:C), meaning the attacker can access data beyond the immediate security scope of the VirtualBox application, specifically resulting in unauthorized read access to a subset of accessible data. The vulnerability is addressed in the Oracle Critical Patch Update for June 2026.

Affected products

  • Oracle VM VirtualBox 7.2.8

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats