CVE-2026-21640

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error.
References
Link Resource
https://hackerone.com/reports/3445332 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:aquaplatform:revive_adserver:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:18

Type Values Removed Values Added
Summary
  • (es) El miembro de la comunidad de HackerOne Faraz Ahmed (PakCyberbot) ha informado de una inyección de cadena de formato en la configuración de Revive Adserver. Cuando se utilizan combinaciones de caracteres específicas en una configuración, la consola del usuario administrador podría deshabilitarse debido a un error fatal de PHP.

30 Jan 2026, 20:17

Type Values Removed Values Added
First Time Aquaplatform
Aquaplatform revive Adserver
References () https://hackerone.com/reports/3445332 - () https://hackerone.com/reports/3445332 - Third Party Advisory
CPE cpe:2.3:a:aquaplatform:revive_adserver:*:*:*:*:*:*:*:*

21 Jan 2026, 19:16

Type Values Removed Values Added
CWE CWE-134

20 Jan 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-20 21:16

Updated : 2026-06-17 10:18


NVD link : CVE-2026-21640

Mitre link : CVE-2026-21640

CVE.ORG link : CVE-2026-21640


JSON object : View

Products Affected

aquaplatform

  • revive_adserver
CWE
CWE-134

Use of Externally-Controlled Format String