Junglewise Threat Intelligence

CVE-2026-50739: Revive Adserver improper access control in tracker-campaigns.php

CVE-2026-50739 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source advertisement management system, contains a security flaw that allows low-privileged users to interfere with advertising campaigns they do not own. By exploiting this vulnerability, an attacker can link their own tracking tools to campaigns managed by other users on the same platform. This can lead to data inconsistencies and unauthorized modifications to how advertising performance is tracked across the system.

Technical details

An improper access control vulnerability exists in Revive Adserver 6.0.7 and earlier due to missing ownership validation in the `tracker-campaigns.php` script. While a previous fix (CVE-2026-34913) addressed ownership checks for certain operations, the reverse operation of linking trackers to campaigns remained unprotected. A remote attacker with low-level authenticated access can exploit this by submitting requests that associate their own trackers with campaigns belonging to different managers on the same instance. This results in unauthorized modification of campaign-tracker relationships and inconsistent data ownership within the database.

Affected products

  • Revive Adserver 6.0.7 and earlier

Timeline

  • 2026-06-26: disclosed: NVD publication date

References

Related threats