Description
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Memory Corruption leading to potential code execution
Action: Immediate Patch
AI Analysis

Impact

The issue is a memory corruption flaw in the gf_bt_report function of the MP4Box component in GPAC. The flaw can be triggered remotely, allowing an attacker to overwrite memory and potentially gain arbitrary code execution or crash the process. The vulnerability is identified as CWE‑119, which signifies improper handling of a buffer boundary.

Affected Systems

The flaw affects all GPAC releases up to the commit identified by f1219cde, which includes versions prior to abi‑16.23. Users running MP4Box on any of these versions should be aware that the vulnerability exists.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is <1%, indicating a low probability of exploitation, but the public exploit suggests that the vulnerability can still be targeted. The flaw is not listed in the CISA KEV catalog. An attacker can exploit the issue remotely by supplying crafted input to the MP4Box tool, and because the memory corruption could lead to arbitrary code execution, the risk to confidentiality, integrity, and availability is high. The remote nature of the attack vector emphasizes the need for timely remediation.

Generated by OpenCVE AI on September 15, 2026 at 15:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi-16.23 or later, which includes the applied patch.
  • If upgrading the full release is not possible, apply the commit identified by afca1f1181668d85941d51ed1adf647807d5d975 to the MP4Box source code and rebuild the binaries.
  • If the vulnerability cannot be patched immediately, limit the exposure of MP4Box by restricting network access to trusted hosts and monitoring for anomalous activity.

Generated by OpenCVE AI on September 15, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component.
Title GPAC MP4Box loader_bt.c gf_bt_report memory corruption
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T14:58:18.847Z

Reserved: 2026-09-13T04:55:35.202Z

Link: CVE-2026-90686

cve-icon Vulnrichment

Updated: 2026-09-14T14:58:14.854Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T06:16:58.507

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer