CVE-2026-46874: Infoleak
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Oracle VM VirtualBox 7.2.8from your environment.Uninstall or stop running Oracle VM VirtualBox version 7.2.8 on affected hosts until a vendor fix is available.
- Compensating control
Restrict and harden access to the infrastructure and hosts where Oracle VM VirtualBox runs: limit interactive logons to trusted administrators only, enforce least-privilege for accounts on those hosts, block or restrict management/remote access to those hosts with firewall rules or ACLs to trusted IPs, and isolate affected hosts or networks to prevent lateral movement.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46874?
The severity of CVE-2026-46874 is classified as low with a score of 3.2.
How do I fix CVE-2026-46874?
To fix CVE-2026-46874, upgrade Oracle VM VirtualBox to the latest version beyond 7.2.8.
What component is affected by CVE-2026-46874?
CVE-2026-46874 affects the Core component of the Oracle VM VirtualBox product.
What is the potential impact of CVE-2026-46874?
The potential impact of CVE-2026-46874 is that a high privileged attacker can compromise Oracle VM VirtualBox through an exploit.
When was CVE-2026-46874 published?
CVE-2026-46874 was published on June 16, 2026.