Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/3672641 |
|
History
Wed, 24 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Session ID Reuse Allows Authentication Bypass in Revive Adserver XML‑RPC API |
Wed, 24 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Session ID Reuse Allows Authentication Bypass in Revive Adserver XML‑RPC API |
Wed, 24 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Session ID Reuse Vulnerability in Revive Adserver XML‑RPC API |
Wed, 24 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Session ID Reuse Vulnerability in Revive Adserver XML‑RPC API |
Tue, 23 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Revive Adserver Session ID Reuse Vulnerability Enables Unauthorized API Access |
Tue, 23 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revive
Revive adserver |
|
| Vendors & Products |
Revive
Revive adserver |
Tue, 23 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Revive Adserver Session ID Reuse Vulnerability Enables Unauthorized API Access |
Tue, 23 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably. | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2026-06-23T16:14:38.592Z
Updated: 2026-06-23T17:24:49.856Z
Reserved: 2026-03-31T15:00:06.522Z
Link: CVE-2026-34917
Updated: 2026-06-23T17:24:43.648Z
No data.
No data.
ReportizFlow