Junglewise Threat Intelligence

CVE-2026-34914: Revive Adserver blind SQL injection in zone-include.php

CVE-2026-34914 · Severity: high · CVSS 8.3 · Published 2026-06-23

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source platform for managing digital advertising, contains a security flaw that could allow an authorized user with low-level permissions to interfere with the underlying database. By exploiting this vulnerability, an attacker could potentially extract sensitive information or modify data, leading to a loss of data integrity and potential service disruption. Organizations using this software should ensure they have updated to a version beyond 6.0.6 to mitigate this risk.

Technical details

A blind SQL injection vulnerability exists in Revive Adserver versions 6.0.6 and earlier within the 'zone-include.php' script. The root cause is the improper neutralization of special elements in the 'clientid' parameter, which is used in database queries without adequate sanitization (CWE-89). An attacker with low-privileged network access can exploit this flaw to perform blind SQL injection attacks. This could lead to unauthorized data retrieval, modification, or deletion within the database. The vendor has addressed this issue by improving input validation for all parameters processed by the affected script.

Affected products

  • Revive Adserver <= 6.0.6

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory

References

Related threats