VYPR
High severity8.8NVD Advisory· Published Nov 20, 2025· Updated Jun 17, 2026

CVE-2025-48986

CVE-2025-48986

Description

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Affected products

3
  • cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*range: <=5.5.2
    • (no CPE)range: <= 6.0.1
    • (no CPE)range: 5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.