CVE-2026-50743
Last modified
CVE-2026-50743 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Revive | Adserver | <= 6.0.7 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-50743?
How severe is CVE-2026-50743?
How do I fix CVE-2026-50743?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50738A use-after-free condition exists in pglogical's worker sign…7.7
- CVE-2026-50739A bypass for CVE‑2026‑34913 exists with proper ownership val…4.3
- CVE-2026-5074The ARMember Premium plugin for WordPress is vulnerable to S…6.5
- CVE-2026-50740A missing sanitisation vulnerability of user input in the zo…5.4
- CVE-2026-50741Bypass to the fix for CVE-2026-34916. Variants of such vecto…8.8
- CVE-2026-50742A stored XSS vulnerabilities exists in the `maintenance-acl-…5.4
- CVE-2026-50744A bypass to the admin‑only restriction of the XML‑RPC API in…4.3
- CVE-2026-50745A missing sanitisation vulnerability exists with user input …6.1
- CVE-2026-50746A malicious actor with access to the network could exploit a…10
- CVE-2026-50747A malicious actor with access to the network and low privile…9.9
- CVE-2026-50748A malicious actor with access to the network and low privile…9.9
- CVE-2026-50749Improper Authorization vulnerability in Apache Answer. This…6.5
Are you affected by CVE-2026-50743?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
