Access Control Vulnerability in Revive Adserver
CVE-2026-34913
4.3MEDIUM
What is CVE-2026-34913?
In Revive Adserver, a missing access control check in the campaign-trackers.php script allows low-privileged users to link trackers to campaigns that are owned by other managers. This oversight leads to inconsistent ownership relationships between trackers and campaigns. To address this issue, ownership validation has been implemented, ensuring that only trackers owned by the same advertiser can be linked to their respective campaigns.
Affected Version(s)
Adserver 0 <= 6.0.6
