Junglewise Threat Intelligence

CVE-2026-46974: Oracle VM VirtualBox improper access control in Core

CVE-2026-46974 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

A vulnerability in Oracle VM VirtualBox's core component could allow a high-privileged user on the host system to take complete control of the virtualization software. VirtualBox is used to run multiple operating systems on a single physical machine; a successful exploit could allow an attacker to break out of the intended isolation and impact the host or other virtual machines. While difficult to execute, this flaw poses a significant risk to the confidentiality and integrity of the entire virtualized environment.

Technical details

This vulnerability (CWE-284) exists in the Core component of Oracle VM VirtualBox version 7.2.8. It is classified as an improper access control issue that requires the attacker to have local logon credentials and high privileges on the infrastructure where VirtualBox is executing. The exploit is considered difficult to perform (High Attack Complexity) but results in a scope change (Status: Changed), meaning an attacker can potentially move beyond the VirtualBox application to affect the host or other guest systems. Successful exploitation grants full control over the VirtualBox environment, impacting confidentiality, integrity, and availability.

Affected products

  • Oracle VM VirtualBox 7.2.8

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats