Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://hackerone.com/reports/3445332 |
|
Sat, 18 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Format String Injection in Revive Adserver Settings Causing Admin Console Crash |
Fri, 30 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aquaplatform
Aquaplatform revive Adserver |
|
| CPEs | cpe:2.3:a:aquaplatform:revive_adserver:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aquaplatform
Aquaplatform revive Adserver |
|
| Metrics |
cvssV3_1
|
Wed, 21 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-134 | |
| Metrics |
ssvc
|
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revive
Revive adserver |
|
| Vendors & Products |
Revive
Revive adserver |
Tue, 20 Jan 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-01-21T18:52:43.635Z
Reserved: 2026-01-01T15:00:02.339Z
Link: CVE-2026-21640
Updated: 2026-01-21T18:35:26.346Z
Status : Analyzed
Published: 2026-01-20T21:16:06.063
Modified: 2026-01-30T20:17:33.390
Link: CVE-2026-21640
No data.
OpenCVE Enrichment
Updated: 2026-04-18T15:45:04Z