[REVIVE-SA-2026-002] Revive Adserver Vulnerabilities
Matteo Beccati ·
======================================================================== Revive Adserver Security Advisory REVIVE-SA-2026-002 ------------------------------------------------------------------------ https://www.revive-adserver.com/security/revive-sa-2026-002 ------------------------------------------------------------------------ Date: 2026-06-03 Risk Level: Medium to High Applications affected: Revive Adserver Versions affected: <= 6.0.6 Versions not affected: >= 6.0.7 Website: https://www.revive-adserver.com/ ======================================================================== ======================================================================== 1. Improper Access Control ======================================================================== Vulnerability Type: CWE-284: Improper Access Control CVE-ID: CVE-2026-34912 Risk level: Medium CVSS Base Score: 4.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N ======================================================================== Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3650504 https://github.com/revive-adserver/revive-adserver/commit/e1c9b8478 https://cwe.mitre.org/data/definitions/284.html ======================================================================== 2. Improper Access Control ======================================================================== Vulnerability Type: CWE-284: Improper Access Control CVE-ID: CVE-2026-34913 Risk level: Medium CVSS Base Score: 4.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N ======================================================================== Description ----------- relationships. Resolution ---------- References ---------- https://hackerone.com/reports/3650582 https://github.com/revive-adserver/revive-adserver/commit/f1b5e8504 https://cwe.mitre.org/data/definitions/284.html ======================================================================== 3. Blind SQL Injection ======================================================================== Vulnerability Type: CWE-89: SQL Injection CVE-ID: CVE-2026-34914 Risk level: High CVSS Base Score: 8.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H ======================================================================== Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3653196 https://github.com/revive-adserver/revive-adserver/commit/b541d1d05 https://cwe.mitre.org/data/definitions/89.html ======================================================================== 4. Reflected XSS ======================================================================== Vulnerability Type: CWE-79: Cross-site Scripting CVE-ID: CVE-2026-34915 Risk level: Medium CVSS Base Score: 6.1 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N ======================================================================== Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3653316 https://github.com/revive-adserver/revive-adserver/commit/b541d1d05 https://cwe.mitre.org/data/definitions/79.html ======================================================================== 5. Remote Code Execution ======================================================================== Vulnerability Type: CWE-94: Code Injection CVE-ID: CVE-2026-34916 Risk level: High CVSS Base Score: 8.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H ======================================================================== Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3656781 https://github.com/revive-adserver/revive-adserver/commit/de3525e12 https://cwe.mitre.org/data/definitions/94.html ======================================================================== 6. Improper Authentication ======================================================================== Vulnerability Type: CWE-287: Improper Authentication CVE-ID: CVE-2026-34917 Risk level: Medium CVSS Base Score: 4.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N ======================================================================== Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3672641 https://github.com/revive-adserver/revive-adserver/commit/50c7dd3ba https://cwe.mitre.org/data/definitions/287.html ======================================================================== 7. Stored XSS ======================================================================== Vulnerability Type: CWE-79: Cross-site Scripting CVE-ID: CVE-2026-44956 Risk level: Medium CVSS Base Score: 5.4 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N ======================================================================== Description ----------- Resolution ---------- Proper escaping has been added to the userlog details output. References ---------- https://hackerone.com/reports/3669623 https://github.com/revive-adserver/revive-adserver/commit/6254115b7 https://cwe.mitre.org/data/definitions/79.html ======================================================================== 8. Improper Access Control ======================================================================== Vulnerability Type: CWE-284: Improper Access Control CVE-ID: CVE-2026-44957 Risk level: Medium CVSS Base Score: 4.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N ======================================================================== Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3677576 https://github.com/revive-adserver/revive-adserver/commit/5860e2f86 https://cwe.mitre.org/data/definitions/284.html ======================================================================== 9. Improper Access Control ======================================================================== Vulnerability Type: CWE-284: Improper Access Control CVE-ID: CVE-2026-44958 Risk level: Medium CVSS Base Score: 4.3 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N ======================================================================== Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3678828 https://github.com/revive-adserver/revive-adserver/commit/2af365841 https://cwe.mitre.org/data/definitions/284.html ======================================================================== 10. Remote Code Execution ======================================================================== Vulnerability Type: CWE-94: Code Injection CVE-ID: CVE-2026-44959 Risk level: High CVSS Base Score: 8.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H ======================================================================== Description ----------- Resolution ---------- References ---------- https://hackerone.com/reports/3744200 https://github.com/revive-adserver/revive-adserver/commit/6c6161420 https://cwe.mitre.org/data/definitions/94.html ======================================================================== 11. Stored XSS ======================================================================== Vulnerability Type: CWE-79: Cross-site Scripting CVE-ID: CVE-2026-44960 Risk level: Medium CVSS Base Score: 5.4 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N ------------------------------------------------------------------------ Description ----------- the username would be executed due to missing output sanitisation. Resolution ---------- Proper escaping has been added to the audit log details output. References ---------- https://hackerone.com/reports/3680090 https://github.com/revive-adserver/revive-adserver/commit/27bb9a8f5 https://cwe.mitre.org/data/definitions/79.html ======================================================================== 12. Incomplete List of Disallowed Inputs ======================================================================== Vulnerability Type: CWE-184: Incomplete List of Disallowed Inputs CVE-ID: CVE-2026-44961 Risk level: Medium CVSS Base Score: 5.4 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N ------------------------------------------------------------------------ Description ----------- HackerOne community member barcrange (3l4) has reported that the XML‑RPC API CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Resolution ---------- Proper validation has been added where it was missing. References ---------- https://hackerone.com/reports/3680090 https://github.com/revive-adserver/revive-adserver/commit/229cf361b https://cwe.mitre.org/data/definitions/184.html ======================================================================== Solution ======================================================================== ======================================================================== Contact Information ======================================================================== The security contact for Revive Adserver can be reached at: <security AT revive-adserver DOT com>. Please review https://www.revive-adserver.com/security/ before doing so. -- Matteo Beccati On behalf of the Revive Adserver Team https://www.revive-adserver.com/ _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/