Description
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.
Published: 2026-01-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

The vulnerability in the tracker-delete.php script of Revive Adserver allows users who have permission to delete trackers to remove trackers belonging to other user accounts. This bypasses the intended ownership checks and results in unauthorized deletion of data, potentially causing loss of tracking information, disruption of advertising services, and violation of data integrity. The weakness corresponds to improper authorization (CWE‑285).

Affected Systems

The flaw affects Revive Adserver by Revive. No specific version information is supplied, so any deployment of Revive Adserver that includes the tracker‑delete.php script before the vendor’s fix is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of < 1% shows a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. An attacker would need to be an authenticated user who has delete permissions and target the tracker‑delete.php endpoint. The fact that this endpoint is accessed over HTTP is inferred from typical web application behavior and is not explicitly stated in the advisory. This flaw only allows deletion of data and does not grant code execution or privilege escalation, limiting impact to integrity and availability of the trackers owned by other accounts.

Generated by OpenCVE AI on April 18, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Revive Adserver version that contains the authorization fix for tracker-delete.php.
  • Restrict delete permissions to administrators or trusted accounts for critical tracking data.
  • Implement logging and audit mechanisms to detect and review unexpected tracker deletions.

Generated by OpenCVE AI on April 18, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 18 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Revive Adserver Tracker Deletion

Fri, 30 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Aquaplatform
Aquaplatform revive Adserver
CPEs cpe:2.3:a:aquaplatform:revive_adserver:*:*:*:*:*:*:*:*
Vendors & Products Aquaplatform
Aquaplatform revive Adserver
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Wed, 21 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 21 Jan 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Revive
Revive adserver
Vendors & Products Revive
Revive adserver

Tue, 20 Jan 2026 21:00:00 +0000

Type Values Removed Values Added
Description HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.
References
Metrics cvssV3_0

{'score': 7.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Aquaplatform Revive Adserver
Revive Adserver
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-01-21T18:52:48.506Z

Reserved: 2026-01-01T15:00:02.340Z

Link: CVE-2026-21641

cve-icon Vulnrichment

Updated: 2026-01-21T18:39:15.272Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T21:16:06.187

Modified: 2026-01-30T20:15:53.850

Link: CVE-2026-21641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T16:00:04Z

Weaknesses