CVE-2026-21641
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.
Vendor
Product
CWE
Yayın Tarihi
2026-01-20 21:16:06
Güncelleme
2026-01-30 20:15:53
Source Identifier
support@hackerone.com
KEV Date Added
-