CVE-2026-44958
NONE EPSS 16.8%
Published Jun 23, 20261w ago · Modified Jun 23, 20261w ago
Published Jun 23, 2026 1w ago
Last Modified Jun 23, 2026 1w ago
Description
An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten solely based on banner edit permissions. The status field has been removed from the hidden form fields in the banner edit screen.
Threat Intelligence
EPSS Exploit Probability
16.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-284
References 1
- hackerone.com https://hackerone.com/reports/3678828
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.