CVE Explorer
CVE-2026-44958
An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten solely based on banner edit permissions. The status field has been removed from the hidden form fields in the banner edit screen.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Adserver","vendor":"Revive","versions":[{"lessThanOrEqual":"6.0.6","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:38e0b96b0d1e84472926b1fe452ac706a65d84b1ee5cb959b79e31942cc153ce · sha256:68bbe7b31244aedf… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","version":"3.0"},"metric_type":"cvssV3_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:38e0b96b0d1e84472926b1fe452ac706a65d84b1ee5cb959b79e31942cc153ce · sha256:68bbe7b31244aedf… · /containers/cna/metrics/0/cvssV3_0
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284 Improper Access Control - Generic","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:38e0b96b0d1e84472926b1fe452ac706a65d84b1ee5cb959b79e31942cc153ce · sha256:68bbe7b31244aedf… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://hackerone.com/reports/3678828"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:38e0b96b0d1e84472926b1fe452ac706a65d84b1ee5cb959b79e31942cc153ce · sha256:68bbe7b31244aedf… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.