CVE-2026-92473Low· 3.3▾ TwilightPoC availableA vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to b…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 18.2 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Exploit / PoC code exists
A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version abi-16.24 is sufficient to resolve this issue. The identifier of the patch is e34f4ba349d55cd1849f0bcf4cf46552732e2db7. It is suggested to upgrade the affected component.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92474Low· 3.3A security flaw has been discovered in GPAC 26.08-DEV
CVE-2026-92472Low· 3.3A vulnerability was determined in GPAC 26.08-DEV
CVE-2026-91087High· 7.3A flaw has been found in GPAC up to f1219cde
CVE-2026-90825Low· 3.3A vulnerability was found in GPAC 26.07.0
CVE-2026-90827Low· 3.3A vulnerability was identified in GPAC 26.07.0
CVE-2026-90793Medium· 5.4A vulnerability has been found in GPAC up to f1219cde