Junglewise Threat Intelligence

CVE-2026-44958: Revive Adserver access control bypass in banner-edit.php

CVE-2026-44958 · Severity: medium · CVSS 5.4 · Published 2026-06-23

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source advertisement management system, contains a flaw that allows unauthorized users to change the status of advertisements. Specifically, users with basic advertiser-level access can activate or deactivate banners even if they have not been granted the specific permissions to do so. This could lead to unauthorized changes in ad campaigns, potentially impacting advertising revenue or campaign operations.

Technical details

An improper access control vulnerability (CWE-284) exists in Revive Adserver versions 6.0.6 and earlier within the banner-edit.php script. The application incorrectly allowed the banner status to be overwritten based solely on general banner edit permissions rather than specific status-change authorizations. This was facilitated by the inclusion of the status field in hidden form fields on the banner edit screen, which could be manipulated by an authenticated advertiser-level attacker. The vulnerability has been addressed by removing the status field from the hidden form fields in the banner edit interface.

Affected products

  • Revive Adserver 6.0.6 and earlier

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory

References

Related threats