CVE-2025-52670

MEDIUM

Revive-adserver Revive Adserver < 5.5.2 - Missing Authorization

Title source: rule
STIX 2.1

Description

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://hackerone.com/reports/3401612

Scores

CVSS v3 6.5
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-862
Status published
Products (1)
revive-adserver/revive_adserver < 5.5.2
Published Nov 20, 2025
Tracked Since Feb 18, 2026