Junglewise Threat Intelligence

CVE-2026-34916: Revive Adserver PHP code injection in delivery limitations

CVE-2026-34916 · Severity: high · CVSS 8.8 · Published 2026-06-23

Technologies: Revive-Adserver Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source platform for managing digital advertising, contains a security flaw that allows users with low-level access to execute malicious code on the server. By manipulating how delivery limitations are saved, an attacker can gain full control over the system, potentially leading to data theft, service disruption, or the distribution of malicious advertisements. This vulnerability poses a significant risk to the integrity of the advertising platform and the security of the underlying server infrastructure.

Technical details

A code injection vulnerability (CWE-94) exists in Revive Adserver versions 6.0.6 and earlier due to insufficient validation of the 'logical' parameter when saving delivery limitations. An authenticated attacker with low-level privileges can inject malicious PHP code into the 'compiledlimitations' database field. This code is subsequently executed by the server during the banner delivery process. The attack is reachable over the network and does not require user interaction, though it does require valid (low-privileged) credentials. The issue has been addressed by improving input sanitization to ensure the parameter is properly validated.

Affected products

  • Revive Adserver Revive Adserver 6.0.6 and earlier

Timeline

  • 2026-06-23: advisory: NVD publication date
  • 2026-06-23: disclosed: HackerOne report published

References

Related threats