Medium severity6.5NVD Advisory· Published Jan 20, 2026· Updated Jun 17, 2026
CVE-2026-21641
CVE-2026-21641
Description
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the tracker-delete.php script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.
Affected products
2Patches
Vulnerability mechanics
References
1- hackerone.com/reports/3445710nvdThird Party Advisory
News mentions
0No linked articles in our index yet.