High severity8.8NVD Advisory· Published Nov 20, 2025· Updated Jun 17, 2026
CVE-2025-48986
CVE-2025-48986
Description
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.
Affected products
3cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*range: <=5.5.2
- (no CPE)range: <= 6.0.1
- (no CPE)range: 5
Patches
Vulnerability mechanics
References
1- hackerone.com/reports/3398283nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.