๐Ÿ” CVE Alert

CVE-2026-7686

MEDIUM 5.3

eyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access control

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in eyeo Adblock Plus up to 4.36.2 on Chrome. Affected by this vulnerability is the function postMessage of the file premium.preload.js of the component Legacy Premium Activation. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been made public and could be used. Upgrading the affected component is recommended. The vendor provides additional details: "The affected code path is a legacy Premium activation flow that has been deprecated. eyeo has already migrated to a new user account-based licensing system. The exploit does not grant permanent Premium access. The licensing server issues a short-lived trial license (valid for approximately 24 hours) for any submitted userId. On the next license check, the server validates against a real subscription and the trial expires if no valid subscription is found. The researcher's claim of permanently unlocking all Premium features is therefore incorrect. (...) The old flow has been present for years and has not been weaponized at scale to our knowledge. The risk to eyeo and to users is minimal."

CWE CWE-284 CWE-266
Vendor eyeo
Product adblock plus
Published May 3, 2026
Stay Ahead of the Next One

Get instant alerts for eyeo adblock plus

Be the first to know when new medium vulnerabilities affecting eyeo adblock plus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

eyeo / Adblock Plus
4.36.0 4.36.1 4.36.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/360856 vuldb.com: https://vuldb.com/vuln/360856/cti vuldb.com: https://vuldb.com/submit/793551 github.com: https://github.com/xryj920/CVE/blob/main/adblock_plus_CVE_report.md adblockplus.org: https://adblockplus.org/en/download

Credits

๐Ÿ” DRXYJ (VulDB User) VulDB CNA Team