Description
A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 will fix this issue. This patch is called afca1f1181668d85941d51ed1adf647807d5d975. It is recommended to upgrade the affected component.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local denial of service via assertion failure
Action: Patch
AI Analysis

Impact

A vulnerability exists in GPAC MP4Box’s xmt_parse_element function, where a crafted media file can trigger a reachable assertion, causing the tool to terminate unexpectedly. The flaw falls under CWE‑617 and results in a local denial‑of‑service scenario. The impact is limited to the host running MP4Box; no remote exploitation is possible according to the current description.

Affected Systems

The issue affects the GPAC suite, specifically the MP4Box component, in any release prior to the commit f1219cde. The vulnerability is fixed in version abi‑16.23, which incorporates the patch commit afca1f1181668d85941d51ed1adf647807d5d975.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score of 0.00119 (< 1%) shows a very low but non‑zero exploitation probability and the vulnerability is not listed in the CISA KEV catalog. The attack vector is limited to local execution; the tool must be run on the targeted machine, so the impact is confined to the local system. Since the exploit has been publicly disclosed, any local user who has access to MP4Box can trigger a crash by feeding a malicious media file, potentially disrupting services or denying access to legitimate processing.

Generated by OpenCVE AI on September 15, 2026 at 15:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi‑16.23, which contains the patch commit afca1f1181668d85941d51ed1adf647807d5d975.
  • If an upgrade is not immediately possible, restrict the execution of MP4Box to trusted users or environments and limit the ability of untrusted processes to invoke it.
  • Consider disabling or removing MP4Box from untrusted or shared systems until the patch can be applied.

Generated by OpenCVE AI on September 15, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 will fix this issue. This patch is called afca1f1181668d85941d51ed1adf647807d5d975. It is recommended to upgrade the affected component.
Title GPAC MP4Box loader_xmt.c xmt_parse_element assertion
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-617
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T18:00:21.519Z

Reserved: 2026-09-12T19:39:17.993Z

Link: CVE-2026-90611

cve-icon Vulnrichment

Updated: 2026-09-15T17:59:47.407Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T02:17:15.357

Modified: 2026-09-15T19:17:46.223

Link: CVE-2026-90611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:45:19Z

Weaknesses