Unknown · Revive Adserver · CVE-2026-44958
**Name of the Vulnerable Software and Affected Versions**
Revive Adserver versions prior to 6.0.7
**Description**
An access control bypass allows a user with advertiser-level privileges to activate or deactivate a banner, regardless of whether they have been granted the necessary permissions. This occurs because the 'banner-edit.php' script allows the banner status to be overwritten based solely on banner edit permissions. The issue is rooted in the presence of the status field within the hidden form fields of the banner edit screen.
**Recommendations**
Update to a version later than 6.0.6.