π¨ EUVD-2026-39600
π Score: 4.3/10 (CVSS v3.1)
π¦ Product: Adserver
π’ Vendor: Revive
π
Updated: 2026-06-26
π A bypass to the adminβonly restriction of the XMLβRPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session was not...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39600









