Unknown · Revive Adserver · CVE-2026-50744
**Name of the Vulnerable Software and Affected Versions**
Revive Adserver version 6.0.7
**Description**
An authentication bypass exists in the XML-RPC API. The `ox.login()` method returns a session ID cookie in the HTTP headers even when the method returns an error. Because the associated session is not invalidated, the leaked session ID allows unauthorized users to perform subsequent API calls without restrictions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.