CVE-2026-50744: Medium severity Revive Revive Adserver vulnerability

Published Jun 26, 2026
·
Updated

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session was not invalidated. As a result, the leaked session ID could be used to perform subsequent API calls without restrictions.

Affected Software

2 affected components
Revive Revive Adserver=6.0.7
revive-adserver Revive Adserver<6.0.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Revive Adserver to a version that resolves this vulnerability.

    Fixed in 6.0.7
  2. Operational

    Invalidate the leaked session after the ox.login method returns an error (the API call returned a session ID cookie in HTTP headers but the associated session was not invalidated).

Event History

Jun 26, 2026
CVE Published
via MITRE·01:11 AM
Data Sourced
via MITRE·01:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-50744?

The severity of CVE-2026-50744 is medium, with a score of 4.3.

2

How do I fix CVE-2026-50744?

To fix CVE-2026-50744, ensure you update to the latest version of Revive Adserver that addresses this vulnerability.

3

What does CVE-2026-50744 expose?

CVE-2026-50744 exposes a bypass to the admin-only restriction of the XML-RPC API in Revive Adserver.

4

What versions of Revive Adserver are affected by CVE-2026-50744?

CVE-2026-50744 specifically affects Revive Adserver version 6.0.7.

5

What type of attack does CVE-2026-50744 facilitate?

CVE-2026-50744 facilitates potential unauthorized access through a session ID leak in the XML-RPC API.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203