CVE-2026-34912
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.
| CWE | CWE-284 |
| Vendor | revive |
| Product | adserver |
| Published | Jun 23, 2026 |
| Last Updated | Jun 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for revive adserver
Be the first to know when new medium vulnerabilities affecting revive adserver are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Versions
Revive / Adserver
0 ≤ 6.0.6
Credits
🔍 Ahmed Ghadban (DarkyOS)