# CVE-2026-14935

## Summary

- **CVE ID:** CVE-2026-14935
- **Severity:** LOW
- **CVSS Score:** 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **CWE:** CWE-670
- **Published:** Jul 7, 2026
- **Last Modified:** Jul 8, 2026

## Description

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.

## Affected Products

No affected products listed.

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-14935)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2497679)
- [CNA](https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/98)
- [CNA](https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5171)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 14.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._