Impact
A bypass of the previously applied CVE‑2026‑34916 fix allows an attacker to supply an otherwise syntactically correct but disallowed plugin identifier as the type field, or to invoke the ox.setChannelTargeting XML‑RPC method, thereby activating a plugin that should be rejected. The flaw corresponds to CWE‑94 – code injection via untrusted input – and enables execution of arbitrary code in the context of the Revive Adserver server. This allows full compromise of the underlying host operating system.
Affected Systems
Any Revive Adserver deployment that has not applied the CVE‑2026‑34916 patch is potentially vulnerable. The vendor list identifies Revive:Adserver as the affected product, but no specific version range is supplied, so administrators must verify whether their installations include the remediation. All installations that expose the plugin validation endpoint or the XML‑RPC API to external actors remain at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of 4% suggests a low but non‑negligible likelihood of exploitation in the current window. The vulnerability is not listed in the CISA KEV catalog, but that does not reduce its threat. Remote exploitation is possible by sending crafted requests to the plugin validation path or the XML‑RPC endpoint, assuming the server is reachable from an attacker. In typical deployments where the server is internet‑exposed or accessible from untrusted networks, the risk escalates; however, network segmentation or firewall policies can mitigate the attack surface.
OpenCVE Enrichment