CVE-2026-46873: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device)
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a privilege-escalation and full-compromise vulnerability in the VMSVGA device component of Oracle VM VirtualBox 7.2.8. An attacker who already holds a high-privileged account and local access to the host where VirtualBox runs can exploit difficult-to-trigger conditions in the virtual graphics device to fully take over the VirtualBox process, with a scope change meaning impact can spill beyond the VM boundary into the host or sibling workloads. Successful exploitation grants the attacker complete read, write, and availability control over the affected instance. HarborGuard is tracking this advisory for patch availability and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection for CVE-2026-46873 is available across every HarborGuard environment: the CVE is ingested from upstream feeds (NVD, Oracle advisories, and CNA feeds) within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle VM VirtualBox 7.2.8. Any image in a connected registry or CI pipeline that carries the affected package surfaces immediately in the findings list.
AvailableTriage is available with the recorded CVSS 3.1 score of 7.5 (HIGH), weighted against each customer organization's compliance policy to reflect environment-specific risk tolerance and regulatory context. Findings are routed to the team inbox configured for the affected workload so the right owner sees the alert without manual forwarding.
AvailableNo fix version has been published by Oracle for this CVE. HarborGuard re-checks the Oracle advisory and upstream feed on every ingest cycle; the moment a patched release is confirmed, a rebuilt image at that version becomes available automatically. For customers who opt into auto-remediation, the rebuild triggers a regression test run and opens a PR against affected workloads without any manual intervention.
Pending upstreamExploit Conditions
- Network reachabilityNot required
The attacker needs an existing shell or privileged process on the host where VirtualBox executes; no network path to the service is required.
- AuthenticationRequired
A high-privileged (admin-level) account on the host infrastructure is required before the vulnerability can be reached.
- Victim interactionNot required
No user action or social-engineering step is needed; the attacker operates independently once host access is established.
- Attack complexityDetail
Attack complexity is HIGH, meaning the exploit depends on specific environmental conditions or race conditions that make reliable triggering difficult and non-trivial to reproduce.
Blast Radius
- Reads all data accessible to the VirtualBox process, including VM memory contents, guest state, and any secrets loaded into the hypervisor context.
- Writes to or modifies VM configuration, guest memory, and persisted disk state, enabling tampering with guest workloads.
- Crashes or destabilizes the VirtualBox process, taking down any running guest VMs and disrupting dependent services.
- Because the CVSS scope is changed, impact can extend beyond the targeted VM to the host OS or other guests sharing the same hypervisor, broadening the footprint of a successful attack.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-46873 is active for any image carrying Oracle VM VirtualBox 7.2.8, matched on every ingest cycle against registered and pipeline-scanned images. Because Oracle has not yet published a fix version, no patched rebuild is available at this time. HarborGuard monitors the Oracle advisory on each ingest cycle and will make a rebuilt image available automatically the moment a fix is released; customers with auto-remediation enabled will receive the rebuild, a regression test run, and an opened PR against affected workloads without manual steps. In the interim, compensating controls worth considering include restricting host logon rights to reduce the pool of accounts that can reach the vulnerable component, applying OS-level mandatory access controls (such as SELinux or AppArmor profiles) around the VirtualBox process, and isolating hypervisor hosts behind network policy rules that limit lateral movement in the event a host account is compromised.
- Oracle Corporation / Oracle VM VirtualBox7.2.8
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H