CVE-2026-21640
EUVD-2026-332920.01.2026, 21:16
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| aquaplatform | revive_adserver | 6.0.0 ≤ 𝑥 ≤ 6.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References