CVE-2026-90826

LOW Status: Received

CVSS Scores

CVSS v3.x Base Score
2.8
LOW
CVSS v2 Base Score
1.7
LOW

Description

A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 can resolve this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.

Published
September 14, 2026 10:16 PM
Last Modified
September 14, 2026 10:16 PM
Source
[email protected]

Weaknesses (CWE)

CWE-119 CWE-125

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.