Admin API Access Vulnerability in Revive Adserver
CVE-2026-50744
4.3MEDIUM
What is CVE-2026-50744?
Revive Adserver 6.0.7 is affected by an authentication bypass vulnerability within its XML-RPC API. The flaw arises when the API's ox.login method erroneously allows a session ID cookie to be exposed in the HTTP headers, even after an error response is provided. Although the method is supposed to restrict access, the failure to invalidate the session after an error allows malicious actors to exploit the leaked session ID for unauthorized API calls, compromising system integrity. It's essential for users of this version to take immediate action to secure their installations.
Affected Version(s)
Adserver 0 <= 6.0.7
