Out-of-Bounds Read Vulnerability in GPAC MP4Box by GPAC
CVE-2026-90826
Key Information:
Badges
What is CVE-2026-90826?
A vulnerability has been identified in GPAC version 26.07.0, specifically in the gf_node_del function within the scenegraph/base_scenegraph.c file of the MP4Box component. This vulnerability is characterized by out-of-bounds read manipulation, which may permit attackers to exploit the issue, although it is limited to local execution. The vulnerability has been publicly disclosed, and users are encouraged to upgrade to version abi-16.23 to mitigate potential risks. A corresponding patch has been released to address this security concern.
Affected Version(s)
GPAC 26.07.0
GPAC abi-16.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
