Access Control Flaw in Revive Adserver by Revive Software
CVE-2026-34912
4.3MEDIUM
What is CVE-2026-34912?
A security vulnerability in Revive Adserver allows low-privileged users to link their zones to banners or campaigns owned by other managers. This flaw arises due to a missing access control check in the zone-include.php script and the API of Revive Adserver versions 6.0.6 and earlier. Without proper ownership validation, users can easily create inconsistent ownership relationships. Revive Software has addressed this issue by implementing ownership validation mechanisms to enhance security. It is highly recommended that users update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Adserver 0 <= 6.0.6
