PT-2026-51558 · Unknown · Revive Adserver

·

CVE-2026-44958

·

Published

2026-06-23

·

Updated

2026-06-23

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 6.0.7
Description An access control bypass allows a user with advertiser-level privileges to activate or deactivate a banner, regardless of whether they have been granted the necessary permissions. This occurs because the 'banner-edit.php' script allows the banner status to be overwritten based solely on banner edit permissions. The issue is rooted in the presence of the status field within the hidden form fields of the banner edit screen.
Recommendations Update to a version later than 6.0.6.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44958

Affected Products

Revive Adserver