Junglewise Threat Intelligence

CVE-2026-46874: Oracle VM VirtualBox information disclosure in Core component

CVE-2026-46874 · Severity: low · CVSS 3.2 · Published 2026-06-17

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer, contains a security vulnerability in its core component. A highly privileged user already logged into the host computer could exploit this to gain unauthorized access to certain data within the VirtualBox environment. While the risk is limited to data reading, the breach could potentially impact other software running on the same system.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Core component of Oracle VM VirtualBox version 7.2.8. The flaw is easily exploitable by a local attacker with high privileges (e.g., administrative access on the host) and does not require user interaction. Successful exploitation results in a scope change (S:C), meaning the attacker can read a subset of data accessible to VirtualBox that may reside outside the immediate security context of the application. The impact is limited to confidentiality, with no reported impact on system integrity or availability.

Affected products

  • Oracle VM VirtualBox 7.2.8

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats