Authorization Flaw in Revive Adserver Allows Banner Deletion by Unauthorized Users
CVE-2025-52670
What is CVE-2025-52670?
An authorization vulnerability in Revive Adserver versions 5.5.2 and 6.0.1, as well as earlier iterations, allows users to delete banners from other accounts. This oversight in permission verification can lead to unauthorized modifications within the ad management system, potentially affecting multiple users and undermining the integrity of ad campaigns. It is crucial for administrators to apply the necessary updates and review their security settings to mitigate the risk of exploit.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Revive Adserver 6 <= 6.0.1
Revive Adserver 5 <= 5.5.2
Revive Adserver 6.0.2
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
