8.8
/ 10
HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method.
AI Analysis
Bypass vulnerability in Revive Adserver
Basic Information
ID
CVE-2026-50741
Source
hackerone
Published
Jun 26, 2026 at 01:11
Affected Product
Vendor
Revive
Product
Adserver
Affected Versions
Revive Adserver 0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Revive
Product
Adserver