← Vulnerability feed

Vulnerability record · CVE-2025-48986 · published 20 November 2025

CVE-2025-48986: Revive-adserver revive adserver improper access control vulnerability

Revive Adserver · Revive Adserver

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

8.8 CVSS 3.0 High EPSS 0.62% · top 52.2% CWE-284 · Improper access control
8.8CVSS 3.0 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
26 Sep 2026Last modified by NVD

Description

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://hackerone.com/reports/3398283 ExploitIssue TrackingThird Party Advisory
https://hackerone.com/reports/3398283 ExploitIssue TrackingThird Party Advisory

Track CVE-2025-48986 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-9124Revive-adserver revive adserver improper restriction of authentication attempts vulnerabilityRevive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable …EPSS 2.2%9.8CVE-2016-9125Revive-adserver revive adserver vulnerabilityRevive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not inva…EPSS 2.7%9.8CVE-2017-5830Revive-adserver revive adserver deserialization of untrusted data vulnerabilityRevive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.EPSS 3.3%9.0CVE-2016-9470Revive-adserver revive adserver cross-site scripting vulnerabilityRevive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected F…EPSS 2.1%8.8CVE-2026-50741Revive-adserver revive adserver code injection vulnerabilityBypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sen…EPSS 4.9%8.8CVE-2025-52664Revive-adserver revive adserver sql injection vulnerabilitySQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in use…EPSS 0.92%8.8CVE-2016-9127Revive-adserver revive adserver cross-site request forgery vulnerabilityRevive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF atta…EPSS 0.76%8.8CVE-2016-9455Revive-adserver revive adserver cross-site request forgery vulnerabilityRevive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable t…EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2025-48986), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.