Executive brief
Revive Adserver, a popular open-source advertisement management system, contains a security flaw that allows low-privileged users to interfere with advertising campaigns they do not own. By exploiting this vulnerability, an attacker can link their own tracking tools to campaigns managed by other users on the same platform. This can lead to data inconsistencies and unauthorized modifications to how advertising performance is tracked across the system.
Technical details
An improper access control vulnerability exists in Revive Adserver 6.0.7 and earlier due to missing ownership validation in the `tracker-campaigns.php` script. While a previous fix (CVE-2026-34913) addressed ownership checks for certain operations, the reverse operation of linking trackers to campaigns remained unprotected. A remote attacker with low-level authenticated access can exploit this by submitting requests that associate their own trackers with campaigns belonging to different managers on the same instance. This results in unauthorized modification of campaign-tracker relationships and inconsistent data ownership within the database.
Affected products
- Revive Adserver 6.0.7 and earlier
Timeline
- 2026-06-26: disclosed: NVD publication date