Description
A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version abi-16.24 is sufficient to resolve this issue. The identifier of the patch is e34f4ba349d55cd1849f0bcf4cf46552732e2db7. It is suggested to upgrade the affected component.
Published: 2026-09-16
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free (Local Exploit)
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises in GPAC version 26.08‑DEV in the gf_sg_command_del function of the BIFS Handler. It allows a use‑after‑free condition when manipulating commands, which can lead to memory corruption. The effect could be a crash or potential arbitrary code execution if a local attacker can control the data fed to gpac. The CVSS score is 4.8, indicating a moderate severity, but the exploit requires local access and the publicly available proof‑of‑concept demonstrates the possibility of exploitation. This weakness is classified as CWE‑119 and CWE‑416.

Affected Systems

The affected product is GPAC, a multimedia framework, at least the 26.08‑DEV build. No version range is provided beyond this build, and the vendor indicates that upgrading to the abi‑16.24 release, which includes the patch identified by commit e34f4b..., resolves the issue. There are no known impacts on other GPAC versions. The affected component is the BIFS Handler within the scenegraph/commands.c file.

Risk and Exploitability

The risk level is moderate. The exploit requires local execution; it is not remotely reachable and is not listed in CISA's KEV catalog. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. Nevertheless, because the publicly available proof‑of‑concept is available and the flaw can lead to memory corruption, any local user who can run gpac with untrusted data should be considered a potential threat vector. An attacker would need to supply a crafted BIFS file or otherwise influence the command deletion logic to trigger the use‑after‑free. No elevated privileges are required beyond the user running gpac.

Generated by OpenCVE AI on September 18, 2026 at 05:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi‑16.24 or later, which contains the patch commit e34f4ba349d55cd1849f0bcf4cf46552732e2db7.
  • If an upgrade is not feasible, restrict local users from executing gpac with untrusted input or run it in a sandbox environment to prevent the use‑after‑free from affecting other processes.
  • Disable or remove the BIFS feature in gpac configurations if it is not required for your workload, thereby removing the vulnerable code path.

Generated by OpenCVE AI on September 18, 2026 at 05:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version abi-16.24 is sufficient to resolve this issue. The identifier of the patch is e34f4ba349d55cd1849f0bcf4cf46552732e2db7. It is suggested to upgrade the affected component.
Title GPAC BIFS commands.c gf_sg_command_del use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T18:21:21.103Z

Reserved: 2026-09-16T12:14:55.108Z

Link: CVE-2026-92473

cve-icon Vulnrichment

Updated: 2026-09-18T18:21:15.591Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:18:06.583

Modified: 2026-09-18T19:17:17.453

Link: CVE-2026-92473

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:30:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free