Junglewise Threat Intelligence

CVE-2026-46977: Oracle VM VirtualBox information disclosure in VMSVGA device

CVE-2026-46977 · Severity: low · CVSS 3.2 · Published 2026-06-17

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer. A highly privileged user on the host system could exploit this flaw to gain unauthorized access to sensitive data managed by the software. While the risk is rated as low, an exploit could potentially impact other products or systems connected to the virtual environment.

Technical details

This vulnerability is classified as an information disclosure (CWE-200) within the VMSVGA device component of Oracle VM VirtualBox. It is exploitable by a local attacker with high privileges on the infrastructure where VirtualBox is executing. The flaw is characterized by a 'scope change' (S:C), meaning that while the vulnerability exists in VirtualBox, the impact can extend to other products or the host environment. Successful exploitation results in unauthorized read access to a subset of accessible data. The vulnerability is present in version 7.2.8.

Affected products

  • Oracle VM VirtualBox 7.2.8

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats