Junglewise Threat Intelligence

CVE-2026-50742: Revive Adserver stored XSS in maintenance tools

CVE-2026-50742 · Severity: medium · CVSS 4.4 · Published 2026-06-26

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source ad serving platform, contains a security flaw in its maintenance tools. An attacker can inject malicious scripts that may execute when an administrator performs routine system checks. If successful, this could allow the attacker to perform unauthorized actions or steal sensitive information from the administrator's session.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Revive Adserver version 6.0.7 and earlier within the `maintenance-acl-check.php` and `maintenance-banners-check.php` components. The root cause is the failure to properly escape entity names when displaying them during inconsistency detection reports. An attacker with low privileges can inject a payload that resides in the database; however, execution is conditional on an administrator running specific maintenance tools and the system detecting an inconsistency. If triggered, the script executes in the context of the administrator's browser, potentially leading to session hijacking or unauthorized configuration changes.

Affected products

  • Revive Adserver <= 6.0.7

Timeline

  • 2026-06-26: disclosed: CVE published to NVD via HackerOne report

References

Related threats