CVE-2026-34913: Revive Adserver Campaign Tracker Access Control Bypass
Revive Adserver versions 6.0.6 and earlier contain a flaw that allows account users with limited permissions to improperly link tracking tools to advertising campaigns they do not own. The vulnerability stems from inadequate permission checks in the campaign-trackers.php file. An attacker with basic user credentials could reassign trackers across different advertiser accounts, creating ownership confusion and potentially manipulating reporting or tracking data. Patched versions validate that campaigns can only be associated with trackers belonging to the same advertiser, restoring proper access boundaries.
Source data · NVD / CISA · public domain
- CVSS
- 3.0 · 4.3 MEDIUM · CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-284
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-23 / 2026-06-23
NVD description (verbatim)
A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-34913 is an insufficient access control vulnerability (CWE-284) affecting the tracker-to-campaign linking mechanism in Revive Adserver. The campaign-trackers.php script fails to verify that a low-privileged user owns both the tracker and target campaign before permitting the association. An authenticated attacker can exploit this by sending a request to link a tracker belonging to one advertiser's account to a campaign owned by another advertiser, bypassing advertiser-level boundaries. The CVSS 3.0 score of 4.3 (Medium severity, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N) reflects network accessibility, low attack complexity, required authentication, and integrity impact without confidentiality or availability loss.
Business impact
This vulnerability enables unauthorized modification of campaign tracking configurations, which can corrupt data integrity and reporting accuracy. An attacker could link competitors' or other advertisers' trackers to campaigns, obfuscating which tracking vendor or internal system is actually monitoring a campaign. This may lead to misattribution of analytics data, compliance violations if tracking relationships become inconsistent with contractual requirements, and operational confusion during audit or forensic review. The impact is primarily administrative and data-integrity focused rather than data exposure or system outage.
Affected systems
Revive Adserver versions 6.0.6 and earlier are affected. Organizations running these versions, particularly those with multiple advertiser accounts or user roles sharing a single Adserver instance, face risk if low-privileged users have access to the campaign linking interface. Multi-tenant or hosted deployments are of particular concern since the vulnerability allows cross-advertiser interference.
Exploitability
Exploitation requires valid user credentials (PR:L) but no special interaction, UI interaction, or elevated privileges. Network accessibility is direct (AV:N), and attack complexity is low (AC:L). However, the attacker must be an existing user of the system; external unauthenticated exploitation is not possible. The attack is straightforward once credentials are obtained, making it a realistic risk in environments where user accounts are shared, compromised, or created with overly permissive roles.
Remediation
Upgrade Revive Adserver to a patched version that includes ownership validation for campaign-tracker associations. The fix ensures that a user can only link trackers to campaigns when both assets are owned by the same advertiser. Verify the exact patched version against the vendor's security advisory before deployment. Test the update in a staging environment to confirm tracking workflows remain uninterrupted.
Patch guidance
Consult the official Revive Adserver security advisory for the specific patched version number and deployment instructions. Apply the update to all instances running version 6.0.6 or earlier. If you cannot patch immediately, implement compensating controls such as restricting campaign-linking permissions to trusted administrator roles only, and monitor the campaign-trackers.php access logs for unusual linking activity. Disable the feature temporarily if operationally feasible.
Detection guidance
Review audit logs or access logs for the campaign-trackers.php script, particularly for requests that link trackers and campaigns owned by different advertisers. Check the campaign_tracker database relationship table for orphaned or cross-advertiser associations created after a suspicious timestamp. Monitor user accounts with low privilege levels for activity on the campaign linking endpoint. Implement a periodic audit report comparing tracker ownership to linked campaign ownership to surface inconsistencies.
Why prioritize this
Although the CVSS score is Medium (4.3), organizations running multi-advertiser Adserver instances should prioritize this patch because it directly affects data integrity and reporting accuracy—core functions of ad delivery infrastructure. The attack surface is internal users or account compromises, making it a realistic threat in environments with multiple stakeholders. Delaying the patch increases the window for accidental or malicious misconfigurations.
Risk score, explained
The CVSS 3.0 score of 4.3 reflects a network-accessible vulnerability that requires authentication and results in integrity impact (tracker-campaign relationship corruption) but no confidentiality breach or availability loss. The score appropriately captures that this is a boundary-crossing issue of moderate severity, not a critical system compromise. Organizations with strict access control requirements or compliance obligations may consider risk elevated beyond the base score due to audit and reporting implications.
Frequently asked questions
Can this be exploited by completely unauthenticated users?
No. The vulnerability requires valid Revive Adserver user credentials. However, any low-privileged user account (not just administrators) can exploit it, making compromised or shared accounts a significant risk vector.
Does this leak advertiser data or passwords?
No. The vulnerability does not expose confidential data. It allows unauthorized modification of tracker-campaign relationships, which corrupts administrative data integrity but does not grant access to campaign performance data, credentials, or third-party tracking pixels.
How do I know if my Adserver was exploited?
Review the campaign_tracker association table and audit logs for linking activity. Look for trackers and campaigns that belong to different advertisers but are now linked together. Check access logs for the campaign-trackers.php endpoint for requests from unexpected users or at unusual times.
What is the difference between a tracker and a campaign in Revive Adserver?
A campaign is an advertising placement you want to run. A tracker is a monitoring tool (pixel, script, or conversion tag) used to measure that campaign's performance. Proper ownership validation ensures that each advertiser's campaigns are only linked to their own trackers, preventing cross-advertiser interference.
This analysis is provided for informational purposes only and does not constitute professional security advice. Organizations must independently verify all information against official vendor advisories, test patches in non-production environments, and conduct their own risk assessment. No guarantee is made regarding the completeness or accuracy of this summary beyond the ground-truth source data provided. Consult your security team and vendor documentation before implementing any remediation. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2024-27891MEDIUMArista EOS MACsec + Egress ACL Policy Enforcement Failure
- CVE-2025-24165MEDIUMmacOS Permissions Issue Enables Unexpected System Termination
- CVE-2025-43339MEDIUMmacOS Tahoe Sandbox Access Control Bypass Allows User Data Disclosure
- CVE-2025-46308MEDIUMApple iOS, iPadOS, macOS Authorization Bypass—Sensitive Data Disclosure
- CVE-2026-10152MEDIUMImproper Access Control in TaleLin lin-cms-spring-boot Book Endpoint
- CVE-2026-10172MEDIUMBdtask Multi-Store Inventory 1.0 Unrestricted File Upload Vulnerability
- CVE-2026-10205MEDIUMUnrestricted File Upload in Metasoft MetaCRM 6.4.0 – Exploit Details & Remediation
- CVE-2026-10255MEDIUMPharmacy Sales System Authentication Bypass – SourceCodester 1.0