Description
A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free leading to memory corruption
Action: Patch
AI Analysis

Impact

The vulnerability originates in the gf_node_unregister routine within GPAC MP4Box’s base_scenegraph.c, where a freed memory block can still be accessed. This use‑after‑free condition can lead to memory corruption or a crash when the freed memory is referenced again. The effect is limited to the process memory; no specific privilege escalation or remote impact is described. The weakness is categorized under CWE‑119 and CWE‑416.

Affected Systems

GPAC version 26.07.0, specifically the MP4Box component, is affected. The issue is resolved in release abi‑16.23, which incorporates the patch identified by commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24. All distributions of GPAC that bundle the 26.07.0 version of MP4Box are vulnerable until updated.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score is less than 1%, indicating a very low probability that the vulnerability is being exploited in the wild. The flaw requires local access; no remote exploitation path is described. A public exploit is available, which a local attacker could use to trigger a use‑after‑free that may lead to a crash. The overall risk is confined to environments where GPAC is running and processes untrusted input.

Generated by OpenCVE AI on September 17, 2026 at 19:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi‑16.23 or later to receive patch commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24 if a full package upgrade is not possible
  • Restrict local access to MP4Box, for example by running it under a non‑privileged user or within a sandbox environment
  • If upgrading is not feasible immediately, disable or limit any MP4Box features that process user‑supplied media files to reduce exposure.

Generated by OpenCVE AI on September 17, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.
Title GPAC MP4Box base_scenegraph.c gf_node_unregister use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T19:16:14.083Z

Reserved: 2026-09-13T19:16:41.796Z

Link: CVE-2026-90825

cve-icon Vulnrichment

Updated: 2026-09-15T19:16:09.475Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T22:16:58.100

Modified: 2026-09-15T20:19:20.933

Link: CVE-2026-90825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free