CVE-2025-48986

HIGH

Revive Adserver <6.0.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://hackerone.com/reports/3398283

Scores

CVSS v3 8.8
EPSS 0.0058
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
revive-adserver/revive_adserver < 5.5.2
Published Nov 20, 2025
Tracked Since Feb 18, 2026