Unrated severityNVD Advisory· Published Jan 20, 2026· Updated Jan 21, 2026
CVE-2026-21641
CVE-2026-21641
Description
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the tracker-delete.php script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.