Authorization Bypass in Revive Adserver Tracker Management
CVE-2026-21641
7.1HIGH
What is CVE-2026-21641?
An authorization bypass vulnerability exists in the tracker-delete.php script of Revive Adserver, where users granted permission to delete trackers are incorrectly able to delete trackers that belong to other users. This flaw could allow unauthorized users to manipulate data and disrupt service by deleting critical tracking components, compromising user account integrity and data management.
Affected Version(s)
Revive Adserver 6 <= 6.0.4
