← Back to CVE List
CVE-2026-92472NVD
Vulnerability Summary
A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.24 is sufficient to fix this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. The affected component should be upgraded. This issue is distinct from CVE-2026-90827.
CVSS v4.0 Base Metrics — Score 4.8 (MEDIUM)
Attack VectorLocal
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 3.3 (LOW)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityLow
Affected & Patched Versions
- n/a GPAC >= 26.08-DEV
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/405731
- https://vuldb.com/vuln/405731/cti
- https://vuldb.com/cve/CVE-2026-92472
- https://vuldb.com/submit/941003
- https://github.com/gpac/gpac/issues/3831
- https://github.com/user-attachments/files/30635912/poc_12.zip
- https://github.com/gpac/gpac/commit/e34f4ba349d55cd1849f0bcf4cf46552732e2db7
- https://github.com/gpac/gpac/releases/tag/abi-16.24
- https://github.com/gpac/gpac/