Description
A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.24 is sufficient to fix this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. The affected component should be upgraded. This issue is distinct from CVE-2026-90827.
Published: 2026-09-16
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Use-After‑Free
Action: Patch Upgrade
AI Analysis

Impact

GPAC’s MP4Box component contains a use‑after‑free flaw in the gf_node_deactivate_ex function located in base_scenegraph.c. The bug occurs when the function frees a node that is still referenced elsewhere, allowing an attacker to corrupt memory or cause a crash by supplying crafted data to the function. The vulnerability is a classic buffer over‑read/over‑write (CWE‑119) coupled with improper memory reuse (CWE‑416), and it can be triggered locally by processing malicious media files.

Affected Systems

All installations of GPAC built from the 26.08‑DEV source or earlier releases that include MP4Box are affected. The fix is delivered in the abi‑16.24 release and the specific commit e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Any version prior to abi‑16.24 that runs MP4Box is vulnerable, including the default binary distribution of GPAC.

Risk and Exploitability

The CVSS score of 4.8 places the vulnerability in the low‑to‑moderate range, and the EPSS score of less than 1 % indicates an extremely low overall exploitation probability at the time of this analysis. The flaw is not listed in CISA’s KEV catalog. Attackers must have local access or be able to supply malicious media files to a local instance of MP4Box, so the risk is confined to local users or services that automatically process untrusted media. No remote execution vector is known.

Generated by OpenCVE AI on September 18, 2026 at 06:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi‑16.24 or later to apply the vendor‑supplied patch.
  • If upgrading immediately is not possible, run MP4Box in a restricted sandbox or disable it for processing of untrusted media files.
  • After applying the patch or sandboxing, monitor system stability and logs for signs of memory corruption or crashes and ensure GPAC remains up to date with future releases.

Generated by OpenCVE AI on September 18, 2026 at 06:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.24 is sufficient to fix this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. The affected component should be upgraded. This issue is distinct from CVE-2026-90827.
Title GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T19:39:53.908Z

Reserved: 2026-09-16T12:14:44.571Z

Link: CVE-2026-92472

cve-icon Vulnrichment

Updated: 2026-09-16T19:39:47.939Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:18:06.377

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-92472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free