Unrated severityNVD Advisory· Published Nov 20, 2025· Updated Nov 20, 2025
CVE-2025-48986
CVE-2025-48986
Description
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.
Affected products
2- Range: <=6.0.1
- Revive/Revive Adserverv5Range: 5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.