CVE-2026-44959
HIGHRevive Adserver < 6.0.6 - Improper Control of Generation of Code ('Code Injection')
Title source: ruleDescription
A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed during banner delivery. Input sanitisation has been improved to ensure that unexpected parameters are filtered out.
References (1)
Core 1
Core References
Scores
CVSS v3
8.8
EPSS
0.0047
EPSS Percentile
38.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
Revive/Adserver
< 6.0.6
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026