CVE-2026-50741: Code Injection
Published Jun 26, 2026
·Updated
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as type, or using the ox.setChannelTargeting XML-RPC API method.
Affected Software
1 affected component
revive-adserver Revive Adserver<6.0.8
Event History
Jun 26, 2026
CVE Published
via MITRE·01:11 AM
Data Sourced
via MITRE·01:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-50741?
The severity of CVE-2026-50741 is high, with a score of 8.8.
2
How do I fix CVE-2026-50741?
To fix CVE-2026-50741, ensure that the latest patches from Revive Adserver are applied to mitigate the bypass.
3
What types of attacks are associated with CVE-2026-50741?
CVE-2026-50741 is associated with code injection attacks that can bypass the fix for CVE-2026-34916.
4
What is the risk level of CVE-2026-50741?
CVE-2026-50741 has a risk level of 79, indicating a significant potential impact.
5
Which software is affected by CVE-2026-50741?
CVE-2026-50741 affects the Revive Adserver software.