Junglewise Threat Intelligence

CVE-2026-50743: Revive Adserver CSRF in zone-include.php

CVE-2026-50743 · Severity: medium · CVSS 5.4 · Published 2026-07-20

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source advertising server, is vulnerable to a security flaw that could allow an attacker to manipulate advertising campaigns. By tricking an authenticated administrator into clicking a malicious link, an attacker can link or unlink banners and campaigns to specific zones without the administrator's knowledge. This could lead to unauthorized changes in ad delivery, potentially disrupting revenue or displaying unintended content.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `zone-include.php` script of Revive Adserver version 6.0.7 and below. The application fails to verify CSRF tokens for GET and POST requests that manage the association between banners/campaigns and zones. An attacker can exploit this by inducing an authenticated administrator to visit a malicious webpage or click a link, triggering unauthorized state-changing actions. This allows for the unauthorized linking or unlinking of advertising assets, impacting the integrity and availability of ad delivery configurations.

Affected products

  • Revive Adserver 6.0.7 and earlier

Timeline

  • 2026-07-20: disclosed: CVE published to NVD via HackerOne report

References

Related threats