Impact
A bypass exists that defeats the previous remediation for CVE‑2026‑34916 in Revive Adserver. By supplying a disallowed but otherwise syntactically correct plugin identifier as the type field, or by invoking the ox.setChannelTargeting XML‑RPC method, an attacker can activate a plugin that the system should reject. The flaw aligns with CWE‑94, which concerns code injection or execution via untrusted inputs. Because the bypass allows code to be executed in the adserver’s context, it can lead to full compromise of the underlying host.
Affected Systems
Any Revive Adserver installation that has not applied the CVE‑2026‑34916 fix may be vulnerable. No specific version information is provided, so it is unclear which releases are affected; users should verify whether their installed version includes the patch.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of 2% shows a low probability of exploitation, but the lack of a KEV listing is not a mitigating factor. An attacker can exploit the issue remotely by crafting a request that targets the plugin validation path or the XML‑RPC endpoint. It is inferred from common deployment scenarios that exposure to the internet could increase risk, although this is not explicitly stated in the description. The vulnerability remains a remote‑access threat that can ultimately lead to full system compromise.
OpenCVE Enrichment