CVE 8.8 HIGH

CVE-2026-34916_CVE-2026-34916

8.8 / 10
HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.

AI Analysis

Missing validation of user input allows low-privileged users to inject malicious PHP code

Basic Information

ID CVE-2026-34916
Source hackerone
Published Jun 23, 2026 at 16:14
Modified Jun 23, 2026 at 17:26

Affected Product

Vendor Revive Adserver
Product Revive Adserver
Affected Versions Revive Adserver Revive Adserver 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Revive Adserver
Product Revive Adserver
Version 6.0.6 and earlier

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.