CVE-2026-21640

Publication date

2026-01-20 20:48:47

Family

hackerone

State

PUBLISHED

Description

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error.