CVE-2026-90826 Details
Description
A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 can resolve this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.
An out-of-bounds read vulnerability has been identified in GPAC version 26.07.0, specifically within the MP4Box application. The issue arises in the 'gf_node_del' function of 'scenegraph/base_scenegraph.c', where improper handling of node deletions can lead to memory access violations. This vulnerability is exploitable through local execution, particularly when using the '-nstatx' option with MP4Box to traverse and manipulate an untrusted scene graph, causing a heap-buffer-overflow read error.
Users are advised to upgrade to GPAC version abi-16.23, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gpac/gpac/ | [email protected] | Vendor |
| https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975 | [email protected] | Source CodeVendor |
| https://github.com/gpac/gpac/issues/3812 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/gpac/gpac/releases/tag/abi-16.23 | [email protected] | Release NotesVendor |
| https://github.com/user-attachments/files/30400210/poc_19_nstatx.zip | [email protected] | Broken LinkExploit |
| https://vuldb.com/cve/CVE-2026-90826 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/914951 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403328 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403328/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GPAC | 26.07.0 (semver) |
CPE
Remediation
| |
| GPAC MP4Box | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion