Unknown · Revive Adserver · CVE-2026-34912
**Name of the Vulnerable Software and Affected Versions**
Revive Adserver versions prior to 6.0.7
**Description**
A missing access control check occurs when linking banners or campaigns to a zone. This issue can be triggered through the `zone-include.php` script or via the API. It allows a low-privileged user to link their zones to banners or campaigns owned by other managers on the same instance, leading to inconsistent ownership relationships.
**Recommendations**
Update to version 6.0.7 or later to ensure ownership validation is applied when linking banners and campaigns to zones.