CVE-2026-34916Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-23); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-23: 2Mentions · 2026-06-26: 2Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-23: 2Technical Details · 2026-06-26: 106-2306-26
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-232
Disclosure2
2026-06-262
General1Patch1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - Revive Adserver Code Injection Bypass (CVE-2026-50741) CVE-2026-50741 is a bypass to the previous fix for CVE-2026-34916 in Revive Adserver. An authenticated low-privileged user can still inject malicious PHP code into the delivery limitations by sending a disallowed but valid plugin identifier as the type parameter or by using the ox.setChannelTargeting XML-RPC API method. This allows arbitrary PHP code execution during banner delivery. 👉Affected: Revive Adserver (versions affected by the incomplete fix for CVE-2026-34916) Action: Update to the latest patched version of Revive Adserver.

    Post summary

    The advisory discloses CVE-2026‑50741, details how it bypasses a prior patch, and recommends applying the latest patched version of Revive Adserver.

    0000064
    231 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-50741 Bypass to CVE-2026-34916 Fix via Plugin Identifier and XML-RPC API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50741

    Post summary

    The text references CVE-2026-50741 but provides no additional technical, exploit, or mitigation details, making its content essentially a generic mention.

    0000096
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34916 A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical paramete… https://www.cve.org/CVERecord?id=CVE-2026-34916 ----- Traducción: CVE-2026-34916 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑34916, detailing missing input validation in Revive Adserver that could let low‑privileged users manipulate delivery limits, but it does not include any PoC, exploit code, patch, or evidence of active exploitation.

    0000028
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34916 A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical paramete… https://www.cve.org/CVERecord?id=CVE-2026-34916

    Post summary

    The text discloses CVE‑2026‑34916, a missing input‑validation flaw in Revive Adserver that allows low‑privileged users to abuse delivery limitation settings.

    00000685
    57.7K followersView on X

Explore more