CVE 5.4 MEDIUM

CVE-2026-44958_CVE-2026-44958

5.4 / 10
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Description

An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten solely based on banner edit permissions. The status field has been removed from the hidden form fields in the banner edit screen.

Basic Information

ID CVE-2026-44958
Source hackerone
Published Jun 23, 2026 at 16:14
Modified Jun 23, 2026 at 17:30

Affected Product

Vendor Revive
Product Adserver
Affected Versions Revive Adserver 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.