Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ahmed Ghadban

#32179of 56,330
8.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-51550
4.3
2026-06-23
Unknown · Revive Adserver · CVE-2026-34912
**Name of the Vulnerable Software and Affected Versions** Revive Adserver versions prior to 6.0.7 **Description** A missing access control check occurs when linking banners or campaigns to a zone. This issue can be triggered through the `zone-include.php` script or via the API. It allows a low-privileged user to link their zones to banners or campaigns owned by other managers on the same instance, leading to inconsistent ownership relationships. **Recommendations** Update to version 6.0.7 or later to ensure ownership validation is applied when linking banners and campaigns to zones.
PT-2026-51551
4.3
2026-06-23
Unknown · Revive Adserver · CVE-2026-34913
**Name of the Vulnerable Software and Affected Versions** Revive Adserver versions prior to 6.0.7 **Description** A missing access control check in the 'campaign-trackers.php' script allows a low-privileged user to link their trackers to campaigns owned by other managers on the same instance. This leads to inconsistent ownership relationships. The issue occurs because the system fails to validate that campaigns are only linked to trackers owned by the same advertiser. **Recommendations** Update to version 6.0.7 or later to ensure ownership validation is active.