CVE-2026-34912: Medium severity Revive Adserver Revive Adserver vulnerability
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34912?
The severity of CVE-2026-34912 is rated as medium with a score of 4.3.
How can I mitigate CVE-2026-34912?
To mitigate CVE-2026-34912, ensure that access control checks are implemented properly for linking zones to banners or campaigns.
What are the potential impacts of CVE-2026-34912?
The potential impacts of CVE-2026-34912 include unauthorized linking of banners or campaigns by low-privileged users.
Which versions of Revive Adserver are affected by CVE-2026-34912?
Revive Adserver versions 6.0.6 and earlier are affected by CVE-2026-34912.
Is there an official fix for CVE-2026-34912?
An official fix for CVE-2026-34912 should be sought from the Revive Adserver development team or future software updates.