Description
A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to mitigate this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption via use‑after‑free (CWE-416)
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the GPAC MP4Box component, specifically in the gf_node_deactivate_ex function in base_scenegraph.c. This is a use‑after‑free (CWE‑416) that can also lead to out‑of‑bounds read or write (CWE‑119). A local attacker can manipulate a freed memory region, potentially corrupting data or achieving code execution. The description does not explicitly confirm execution, but the nature of the vulnerability indicates that memory corruption could be exploited for elevated local privileges or crash exploitation.

Affected Systems

The vulnerability affects GPAC (GPAC), specifically the MP4Box tool as shipped in version 26.07.0. The fix is included in the abi-16.23 release, and the patch commit identifier is 49dee5cad329cfed310c1682703df7daa47df31a.

Risk and Exploitability

With a CVSS score of 4.8 the severity is moderate, and the EPSS score is < 1%. The vulnerability requires local access and has a publicly available exploit, but it is not listed in the CISA KEV catalog. The risk is therefore confined to environments where the MP4Box tool can be executed by an untrusted user. Proper mitigation reduces the likelihood to zero by removing the vulnerable code.

Generated by OpenCVE AI on September 17, 2026 at 19:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the authorized GPAC abi-16.23 release or apply the patch commit 49dee5cad329cfed310c1682703df7daa47df31a.
  • Run the MP4Box executable under a restricted non‑privileged account and limit its filesystem permissions to prevent exploitation of freed memory.
  • Monitor system logs for abnormal crashes or attempts to invoke MP4Box from untrusted sources.

Generated by OpenCVE AI on September 17, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to mitigate this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Title GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:34:19.512Z

Reserved: 2026-09-13T19:16:48.220Z

Link: CVE-2026-90827

cve-icon Vulnrichment

Updated: 2026-09-15T13:34:16.508Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T22:16:58.503

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free