Junglewise Threat Intelligence

CVE-2026-34913: Revive Adserver improper access control in campaign-trackers.php

CVE-2026-34913 · Severity: medium · CVSS 4.3 · Published 2026-06-23

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source ad serving platform, contains a security flaw in how it manages campaign trackers. A low-privileged user can bypass access controls to link their own tracking tools to advertising campaigns owned by other managers on the same system. This can lead to data inconsistencies and unauthorized modification of campaign relationships, potentially disrupting advertising operations and reporting.

Technical details

An improper access control vulnerability (CWE-284) exists in the 'campaign-trackers.php' script of Revive Adserver. The application fails to perform adequate ownership validation when a user attempts to link a tracker to a campaign. An authenticated attacker with low privileges can exploit this by submitting requests that associate their trackers with campaigns belonging to different advertisers or managers on the same instance. This results in unauthorized modification of campaign metadata and inconsistent ownership relationships. The issue is resolved in versions following 6.0.6 by implementing strict ownership validation to ensure campaigns only link to trackers owned by the same advertiser.

Affected products

  • Revive Adserver 6.0.6 and earlier

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory

References

Related threats