SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90791

MEDIUM · CVSS 6.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the MP4Box component of GPAC affects versions up to f1219cde, allowing remote attackers to exploit the flaw. This could lead to potential arbitrary code execution or application crashes. Organizations using GPAC should prioritize upgrading to version abi-16.23 to mitigate the risk associated with this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90791
Severity
MEDIUM
CVSS
6.3
EPSS
N/A

Original NVD Description

A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to resolve this issue. The patch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.