Unknown · Revive Adserver · CVE-2026-50739
**Name of the Vulnerable Software and Affected Versions**
Revive Adserver versions prior to 6.0.8
**Description**
An ownership validation bypass exists in the reverse operation of linking campaigns and trackers via the `tracker-campaigns.php` script. This flaw allows a low-privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships.
**Recommendations**
Update to version 6.0.8 or later.
Restrict access to the `tracker-campaigns.php` script to authorized administrators until the update is applied.