CVE-2025-48986: High severity Revive Adserver vulnerability
Published Nov 20, 2025
·Updated
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.
Affected Software
3 affected components
Revive Adserver<5.5.2, <6.0.1
revive-adserver Revive Adserver<=5.5.2
revive-adserver Revive Adserver>=6.0.0<=6.0.1
Event History
Nov 20, 2025
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionSeverity
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48986?
CVE-2025-48986 has been classified as a high-severity vulnerability due to its potential for account takeover.
2
How do I fix CVE-2025-48986?
To fix CVE-2025-48986, it is recommended to upgrade to Revive Adserver version 6.0.2 or later.
3
Who is affected by CVE-2025-48986?
CVE-2025-48986 affects users of Revive Adserver versions 5.5.2, 6.0.1, and earlier.
4
What can an attacker do with CVE-2025-48986?
An attacker can exploit CVE-2025-48986 to change other users' email addresses and potentially take over their accounts.
5
Is CVE-2025-48986 a known vulnerability?
Yes, CVE-2025-48986 is a known vulnerability that has been reported and acknowledged in security databases.