CVE-2025-52670

MEDIUM

Revive Adserver < 5.5.2 - Authorization Bypass via Banner Deletion

Title source: llm
STIX 2.1

Description

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://hackerone.com/reports/3401612

Scores

CVSS v3 6.5
EPSS 0.0027
EPSS Percentile 19.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-862
Status published
Products (1)
revive-adserver/revive_adserver < 5.5.2
Published Nov 20, 2025
Tracked Since Feb 18, 2026