CVE-2026-34912
Deferred Deferred - Pending Action
Missing Access Control in Revive Adserver Linking Zones

Publication date: 2026-06-23

Last updated on: 2026-06-23

Assigner: HackerOne

Description
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-23
Last Modified
2026-06-23
Generated
2026-06-23
AI Q&A
2026-06-23
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
revive_adserver revive_adserver to 6.0.6 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Mitigation Strategies

To mitigate this vulnerability, ensure that you upgrade Revive Adserver to a version later than 6.0.6 where ownership validation has been added. This validation ensures that banners and campaigns can only be linked to zones managed by the same account, preventing low-privileged users from linking zones to banners or campaigns owned by other managers.

Executive Summary

This vulnerability is due to a missing access control check in Revive Adserver version 6.0.6 and earlier. Specifically, when linking banners or campaigns to a zone through the zone-include.php script or via the API, a low-privileged user can link their zones to banners or campaigns owned by other managers on the same instance.

This results in inconsistent ownership relationships because the system does not properly verify that the banners and campaigns belong to the same account managing the zone.

To fix this, ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.

Impact Analysis

This vulnerability allows a low-privileged user to link their zones to banners or campaigns owned by other managers, which can cause inconsistent ownership relationships within the Revive Adserver instance.

While it does not directly impact confidentiality or availability, it can lead to integrity issues by allowing unauthorized linking of advertising assets, potentially causing confusion or misuse of advertising campaigns.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-34912. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart