SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91087

HIGH · CVSS 7.3 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the GPAC Compositor component can be exploited remotely, potentially allowing attackers to execute arbitrary code. Organizations using affected versions should prioritize upgrading to version abi-16.24 to mitigate the risk, as the exploit is publicly available. Immediate action is recommended to protect systems from potential compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91087
Severity
HIGH
CVSS
7.3
EPSS
0.37%

Original NVD Description

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is advised.