Description
A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 can resolve this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.
Published: 2026-09-14
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read in GPAC MP4Box component
Action: Apply Patch
AI Analysis

Impact

A buffer under-read in the gf_node_del function of GPAC's MP4Box component causes an out-of-bounds read that can expose internal memory contents. The flaw lies in the scenegraph/base_scenegraph.c file and is classified as a local memory read vulnerability (CWE‑119 and CWE‑125). An attacker who can control the environment and execute MP4Box locally may read restricted memory, potentially revealing sensitive data or affecting program stability.

Affected Systems

The vulnerability affects GPAC products, specifically MP4Box, in version 26.07.0. The fix is available in version abi‑16.23 or later. The affected vendor is GPAC. No other vendor or product variants are listed as impacted.

Risk and Exploitability

The CVSS score of 2.4 indicates low severity. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploit is publicly disclosed and requires local execution privileges; an attacker would need to run or influence MP4Box on the host. Because the flaw only allows a read, its impact is limited to potential memory data leakage and program instability, but the overall risk remains low for typical use cases.

Generated by OpenCVE AI on September 17, 2026 at 19:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi‑16.23 or later (or apply the patch commit afca1f1181668d85941d51ed1adf647807d5d975).
  • Restrict local execution of MP4Box by limiting file permissions or running the tool in a sandboxed environment to reduce the attack surface.
  • Monitor system logs for crashes or abnormal memory reads that might indicate exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 19:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 can resolve this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.
Title GPAC MP4Box base_scenegraph.c gf_node_del out-of-bounds
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 2.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T16:22:29.685Z

Reserved: 2026-09-13T19:16:45.118Z

Link: CVE-2026-90826

cve-icon Vulnrichment

Updated: 2026-09-16T16:22:19.693Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T22:16:58.303

Modified: 2026-09-16T17:18:17.940

Link: CVE-2026-90826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read