Executive brief
Revive Adserver, a popular open-source platform for managing digital advertisements, contains a security flaw that allows attackers to bypass previous security fixes. By exploiting this vulnerability, an attacker with basic user access can execute unauthorized code on the server. This could lead to a complete takeover of the advertising platform, resulting in the theft of sensitive data, disruption of ad delivery, or the distribution of malicious content to website visitors.
Technical details
Revive Adserver (up to version 6.0.7) is vulnerable to a bypass of the fix for CVE-2026-34916, leading to improper control of generation of code (CWE-94). The vulnerability exists because the previous security patch can be circumvented by providing a disallowed but valid plugin identifier as the 'type' parameter, or by utilizing the 'ox.setChannelTargeting' XML-RPC API method. An attacker with low-privileged network access can exploit this to achieve remote code execution (RCE). The vulnerability was reported via HackerOne and affects versions up to and including 6.0.7.
Affected products
- Revive Adserver <= 6.0.7
Timeline
- 2026-06-26: advisory: NVD publication date