SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91826

MEDIUM · CVSS 4.4 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability in Samsung's rLottie library allows attackers to exploit memory corruption when rendering specially crafted vector animations. This could lead to potential execution of arbitrary code, impacting applications that utilize this library. Organizations using rLottie, particularly those in animation or graphics processing, should prioritize addressing this vulnerability to mitigate associated risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91826
Severity
MEDIUM
CVSS
4.4
EPSS
0.11%

Original NVD Description

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.