{"id":"CVE-2026-90826","title":"A vulnerability was determined in GPAC 26.07.0","summary":"A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to…","severity":"low","cvss":2.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","cwe":["CWE-119","CWE-125"],"product":"GPAC","affected":["GPAC 26.07.0"],"published":"2026-09-14","updated":"2026-09-16","sourceUpdated":"2026-09-16T17:18:17.940","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90826","references":[{"url":"https://github.com/gpac/gpac/","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/issues/3812","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/releases/tag/abi-16.23","label":"cna@vuldb.com"},{"url":"https://github.com/user-attachments/files/30400210/poc_19_nstatx.zip","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90826","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/914951","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403328","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403328/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00155,"epssPercentile":0.05048,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-16T16:22:14.848813Z"},"ingestedAt":"2026-09-14T22:16:09.897Z","slug":"CVE-2026-90826","body":"## Overview\n\nA vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 can resolve this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":27,"depthScoreParts":{"impact":15.4,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":205576,"id":"CVE-2026-90826","ts":1789578062155,"field":"exploit_available","old":"false","new":"true"}]}