CVE 8.8 HIGH

CVE-2026-44959_CVE-2026-44959

8.8 / 10
HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed during banner delivery. Input sanitisation has been improved to ensure that unexpected parameters are filtered out.

AI Analysis

Missing validation of user input allows for malicious PHP code injection in Revive Adserver

Basic Information

ID CVE-2026-44959
Source hackerone
Published Jun 23, 2026 at 16:14
Modified Jun 23, 2026 at 17:41

Affected Product

Vendor Revive
Product Adserver
Affected Versions Revive Adserver 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Revive
Product Revive Adserver
Version 6.0.6 and earlier

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.