A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/3650582 |
Configurations
No configuration.
History
23 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 17:16
Updated : 2026-06-23 18:17
NVD link : CVE-2026-34913
Mitre link : CVE-2026-34913
CVE.ORG link : CVE-2026-34913
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
