CVE-2026-92473: GPAC BIFS commands.c gf_sg_command_del use after free

Published Sep 16, 2026
·
Updated

A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gfsgcommanddel of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version abi-16.24 is sufficient to resolve this issue. The identifier of the patch is e34f4ba349d55cd1849f0bcf4cf46552732e2db7. It is suggested to upgrade the affected component.

Affected Software

1 affected component
Gpac GPAC=26.08-DEV

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GPAC BIFS Handler (src/scenegraph/commands.c, gf_sg_command_del) to a version that resolves this vulnerability.

    Fixed in abi-16.24Patch e34f4ba349d55cd1849f0bcf4cf46552732e2db7
  2. Compensating control

    Assume the exploit needs to be performed locally; restrict local access to the affected GPAC/BIFS Handler functionality to trusted users/systems.

Event History

Sep 16, 2026
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Systems running the affected GPAC 26.08-DEV component are exposed if a local attacker has the required low-level privileges. The attack vector is local; the provided data does not indicate remote exploitation.

2

What access does an attacker need?

An attacker needs local access and low privileges. No user interaction is required, and the attack complexity is rated low.

3

What version resolves the vulnerability?

Upgrade the affected component to version abi-16.24 or later. The referenced fix is patch e34f4ba349d55cd1849f0bcf4cf46552732e2db7.

4

How urgent is remediation?

The severity is low with a CVSS score of 3.3, and the documented impact is limited to availability. However, public exploit availability is reported, so affected local installations should be upgraded.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203