Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://hackerone.com/reports/3680090 |
|
Wed, 24 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML‑RPC addUser Validation Bypass Enables Impersonation and Stored XSS |
Wed, 24 Jun 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML‑RPC addUser Validation Bypass Enables Impersonation and Stored XSS |
Wed, 24 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML‑RPC API addUser Validation Bypass Enabling Impersonation and Stored XSS |
Wed, 24 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML‑RPC API addUser Validation Bypass Enabling Impersonation and Stored XSS |
Tue, 23 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML‑RPC API addUser Validation Bypass in Revive Adserver Allows User Impersonation and Stored XSS |
Tue, 23 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revive
Revive adserver |
|
| Vendors & Products |
Revive
Revive adserver |
Tue, 23 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML‑RPC API addUser Validation Bypass in Revive Adserver Allows User Impersonation and Stored XSS |
Tue, 23 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing. | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-06-23T17:44:07.348Z
Reserved: 2026-05-08T15:00:02.447Z
Link: CVE-2026-44961
Updated: 2026-06-23T17:33:07.498Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T11:15:04Z