CVE-2025-48986: Revive-Adserver Revive Adserver

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Affected products

  • Revive-Adserver Revive Adserver: up to and including 5.5.2; from 6.0.0, up to and including 6.0.1

Published 2025-11-20. Last modified 2026-09-26.