Low severity2.7NVD Advisory· Published Jan 20, 2026· Updated Jun 17, 2026
CVE-2026-21640
CVE-2026-21640
Description
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error.
Affected products
3- cpe:2.3:a:aquaplatform:revive_adserver:*:*:*:*:*:*:*:*Range: >=6.0.0,<=6.0.4
6+ 1 more
- (no CPE)range: 6
- (no CPE)
Patches
Vulnerability mechanics
References
1- hackerone.com/reports/3445332nvdThird Party Advisory
News mentions
0No linked articles in our index yet.