[REVIVE-SA-2026-003] Revive Adserver Vulnerabilities
Matteo Beccati ·
======================================================================== Revive Adserver Security Advisory REVIVE-SA-2026-003 ------------------------------------------------------------------------ https://www.revive-adserver.com/security/revive-sa-2026-003 ------------------------------------------------------------------------ Date: 2026-06-25 Risk Level: Medium to High Applications affected: Revive Adserver Versions affected: <= 6.0.7 Versions not affected: >= 6.0.8 Website: https://www.revive-adserver.com/ ======================================================================== ======================================================================== 1. Improper Access Control ======================================================================== Vulnerability Type: CWE-284: Improper Access Control CVE-ID: CVE-2026-50739 Risk level: Medium CVSS Base Score: 4.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N ------------------------------------------------------------------------ Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3780709 https://github.com/revive-adserver/revive-adserver/commit/c03a0b6d https://cwe.mitre.org/data/definitions/284.html ======================================================================== 2. Reflected XSS ======================================================================== Vulnerability Type: CWE-79: Cross-site Scripting CVE-ID: CVE-2026-50740 Risk level: Medium CVSS Base Score: 6.1 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N ------------------------------------------------------------------------ Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3780806 https://github.com/revive-adserver/revive-adserver/commit/03d9ad8b https://cwe.mitre.org/data/definitions/79.html ======================================================================== 3. Remote Code Execution ======================================================================== Vulnerability Type: CWE-94: Code Injection CVE-ID: CVE-2026-50741 Risk level: High CVSS Base Score: 8.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H ------------------------------------------------------------------------ Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3780854 https://hackerone.com/reports/3781492 https://github.com/revive-adserver/revive-adserver/commit/3d1485de https://github.com/revive-adserver/revive-adserver/commit/becaf6e7 https://cwe.mitre.org/data/definitions/94.html ======================================================================== 4. Stored XSS ======================================================================== Vulnerability Type: CWE-79: Cross-site Scripting CVE-ID: CVE-2026-50742 Risk level: Medium CVSS Base Score: 4.4 CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N ------------------------------------------------------------------------ Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3781311 https://github.com/revive-adserver/revive-adserver/commit/91abb6ab https://cwe.mitre.org/data/definitions/79.html ======================================================================== 5. Cross-Site Request Forgery ======================================================================== Vulnerability Type: CWE-352: Cross-Site Request Forgery CVE-ID: CVE-2026-50743 Risk level: Medium CVSS Base Score: 5.4 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L ------------------------------------------------------------------------ Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3781691 https://github.com/revive-adserver/revive-adserver/commit/e3c84d6f https://cwe.mitre.org/data/definitions/352.html ======================================================================== 6. Improper Access Control ======================================================================== Vulnerability Type: CWE-284: Improper Access Control CVE-ID: CVE-2026-50744 Risk level: Medium CVSS Base Score: 4.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N ------------------------------------------------------------------------ Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3783738 https://github.com/revive-adserver/revive-adserver/commit/3e04cb4a https://cwe.mitre.org/data/definitions/284.html ======================================================================== 7. Reflected XSS ======================================================================== Vulnerability Type: CWE-79: Cross-site Scripting CVE-ID: CVE-2026-50745 Risk level: Medium CVSS Base Score: 4.7 CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N ------------------------------------------------------------------------ Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3793243 https://github.com/revive-adserver/revive-adserver/commit/a570a0c1 https://cwe.mitre.org/data/definitions/79.html ======================================================================== Solution ======================================================================== ======================================================================== Contact Information ======================================================================== The security contact for Revive Adserver can be reached at: <security AT revive-adserver DOT com>. Please review https://www.revive-adserver.com/security/ before doing so. -- Matteo Beccati On behalf of the Revive Adserver Team https://www.revive-adserver.com/ _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/