Access Control Weakness in Revive Adserver XML-RPC API
CVE-2026-44957
4.3MEDIUM
What is CVE-2026-44957?
A serious access control vulnerability exists in the XML-RPC API of Revive Adserver versions 6.0.6 and earlier. The issue arises from the absence of proper access control checks during various modify operations, enabling users to alter parent entity assignments. This results in mismatched ownership relationships and may allow low-privileged users to exploit the system, particularly when used in conjunction with certain third-party API extensions or existing security flaws. Access control improvements have since been implemented to safeguard these critical functionality areas.
Affected Version(s)
Adserver 0 <= 6.0.6
