Authorization Flaw in Revive Adserver Allows Banner Deletion by Unauthorized Users
CVE-2025-52670

7.1HIGH

Key Information:

Vendor

Revive

Vendor
CVE Published:
20 November 2025

What is CVE-2025-52670?

An authorization vulnerability in Revive Adserver versions 5.5.2 and 6.0.1, as well as earlier iterations, allows users to delete banners from other accounts. This oversight in permission verification can lead to unauthorized modifications within the ad management system, potentially affecting multiple users and undermining the integrity of ad campaigns. It is crucial for administrators to apply the necessary updates and review their security settings to mitigate the risk of exploit.

Affected Version(s)

Revive Adserver 6 <= 6.0.1

Revive Adserver 5 <= 5.5.2

Revive Adserver 6.0.2

References

CVSS V3.0

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52670 : Authorization Flaw in Revive Adserver Allows Banner Deletion by Unauthorized Users