CVE-2026-21641
EUVD-2026-334120.01.2026, 21:16
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| aquaplatform | revive_adserver | 𝑥 ≤ 6.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References