Junglewise Threat Intelligence

CVE-2026-50741: Revive Adserver code injection bypass in XML-RPC API

CVE-2026-50741 · Severity: high · CVSS 8.8 · Published 2026-06-26

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source platform for managing digital advertisements, contains a security flaw that allows attackers to bypass previous security fixes. By exploiting this vulnerability, an attacker with basic user access can execute unauthorized code on the server. This could lead to a complete takeover of the advertising platform, resulting in the theft of sensitive data, disruption of ad delivery, or the distribution of malicious content to website visitors.

Technical details

Revive Adserver (up to version 6.0.7) is vulnerable to a bypass of the fix for CVE-2026-34916, leading to improper control of generation of code (CWE-94). The vulnerability exists because the previous security patch can be circumvented by providing a disallowed but valid plugin identifier as the 'type' parameter, or by utilizing the 'ox.setChannelTargeting' XML-RPC API method. An attacker with low-privileged network access can exploit this to achieve remote code execution (RCE). The vulnerability was reported via HackerOne and affects versions up to and including 6.0.7.

Affected products

  • Revive Adserver <= 6.0.7

Timeline

  • 2026-06-26: advisory: NVD publication date

References

Related threats