Access Control Flaw in Revive Adserver by Revive Software
CVE-2026-34912

4.3MEDIUM

Key Information:

Vendor

Revive

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-34912?

A security vulnerability in Revive Adserver allows low-privileged users to link their zones to banners or campaigns owned by other managers. This flaw arises due to a missing access control check in the zone-include.php script and the API of Revive Adserver versions 6.0.6 and earlier. Without proper ownership validation, users can easily create inconsistent ownership relationships. Revive Software has addressed this issue by implementing ownership validation mechanisms to enhance security. It is highly recommended that users update to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

Adserver 0 <= 6.0.6

References

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Ghadban (DarkyOS)
.