Junglewise Threat Intelligence

CVE-2026-46825: Oracle VM VirtualBox improper access control in VMSVGA device

CVE-2026-46825 · Severity: medium · CVSS 6 · Published 2026-06-17

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

A security vulnerability has been identified in Oracle VM VirtualBox, a popular tool used to run multiple operating systems on a single computer. An attacker with high-level access to the host system could exploit this flaw to modify or delete critical data within the VirtualBox environment. This could lead to data corruption or unauthorized changes that affect the integrity of the virtualized infrastructure.

Technical details

An improper access control vulnerability (CWE-284) exists in the VMSVGA device component of Oracle VM VirtualBox version 7.2.8. The flaw is locally exploitable by an attacker with high privileges (such as an administrator on the host infrastructure) and does not require user interaction. Successful exploitation results in a 'scope change,' meaning the attacker can impact components beyond the immediate VirtualBox environment, specifically gaining unauthorized creation, deletion, or modification access to critical data. While the attack requires local logon, it is considered easily exploitable once that precondition is met.

Affected products

  • Oracle VM VirtualBox 7.2.8

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats