SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-90827

LOW · CVSS 3.3 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A local use-after-free vulnerability exists in the MP4Box component of GPAC 26.07.0, specifically within the gf_node_deactivate_ex function in the base_scenegraph.c file. Successful exploitation could allow an attacker to manipulate memory, potentially leading to application crashes or arbitrary code execution. Users and administrators of GPAC should prioritize upgrading to version abi-16.23 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90827
Severity
LOW
CVSS
3.3
EPSS
0.16%

Original NVD Description

A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to mitigate this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.