Back to overview

CVE-2026-44961

0.0
CVSS 3.0
Description
The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.

Metadata

CVE ID
CVE-2026-44961
State
PUBLISHED
Assigner
hackerone
Reserved
2026-05-08 15:00 UTC
Published
2026-06-23 16:14 UTC
Last updated
2026-06-23 17:44 UTC
Primary CWE
CWE-287
CWE-287 Improper Authentication - Generic
Vendor / Product
Revive / Adserver
Sources
cve.org  ·  NVD

Severity & Metrics

0.0 N/D CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Revive Adserver 0 ≤ 6.0.6
Weakness (CWE)
CWESourceDescription
CWE-287 cna CWE-287 Improper Authentication - Generic
CVSS scores (1)
ScoreSeverityVersionSourceVector
0.0 N/D 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Back to overview