A vulnerability was determined in GPAC 26.08-DEV. (CVE-2026-92472)
A use-after-free vulnerability exists in GPAC 26.08-DEV within the function gf_node_deactivate_ex in the MP4Box component. This vulnerability requires local access to exploit and can cause a denial of service. The issue has a low severity score and is fixed by upgrading to version abi-16.24. No active exploitation in the wild is currently known.
AI Analysis
Technical Summary
CVE-2026-92472 is a use-after-free vulnerability in GPAC 26.08-DEV affecting the function gf_node_deactivate_ex in src/scenegraph/base_scenegraph.c of the MP4Box component. The vulnerability can be triggered by local manipulation, leading to potential application instability or denial of service. The vulnerability is distinct from CVE-2026-90827. A patch identified by commit e34f4ba349d55cd1849f0bcf4cf46552732e2db7 addresses this issue by upgrading to version abi-16.24.
Potential Impact
The vulnerability allows a local attacker to cause a use-after-free condition, which may result in denial of service (application crash). There is no impact on confidentiality or integrity. The CVSS score is 3.3 (low severity). No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade the affected GPAC component to version abi-16.24 or later, which includes the official fix for this vulnerability. No additional mitigation is required.
A vulnerability was determined in GPAC 26.08-DEV. (CVE-2026-92472)
Description
A use-after-free vulnerability exists in GPAC 26.08-DEV within the function gf_node_deactivate_ex in the MP4Box component. This vulnerability requires local access to exploit and can cause a denial of service. The issue has a low severity score and is fixed by upgrading to version abi-16.24. No active exploitation in the wild is currently known.
CVSS v3.1
Score 3.3low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92472 is a use-after-free vulnerability in GPAC 26.08-DEV affecting the function gf_node_deactivate_ex in src/scenegraph/base_scenegraph.c of the MP4Box component. The vulnerability can be triggered by local manipulation, leading to potential application instability or denial of service. The vulnerability is distinct from CVE-2026-90827. A patch identified by commit e34f4ba349d55cd1849f0bcf4cf46552732e2db7 addresses this issue by upgrading to version abi-16.24.
Potential Impact
The vulnerability allows a local attacker to cause a use-after-free condition, which may result in denial of service (application crash). There is no impact on confidentiality or integrity. The CVSS score is 3.3 (low severity). No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade the affected GPAC component to version abi-16.24 or later, which includes the official fix for this vulnerability. No additional mitigation is required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-762r-99p2-593p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-92472"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aab49aa55bf5e2cf5992914
Added to database: 09/17/2026, 02:00:10 UTC
Last enriched: 09/17/2026, 02:41:50 UTC
Last updated: 09/17/2026, 05:01:32 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.