{"id":"CVE-2025-48986","title":"Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.","summary":"Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-284"],"vendor":"revive-adserver","product":"revive_adserver","affected":["revive_adserver <= 5.5.2","revive_adserver >= 6.0.0, <= 6.0.1"],"published":"2025-11-20","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-48986","references":[{"url":"https://hackerone.com/reports/3398283","label":"support@hackerone.com"},{"url":"https://hackerone.com/reports/3398283","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00624,"epssPercentile":0.47694,"ingestedAt":"2026-09-26T00:22:39.977Z","slug":"CVE-2025-48986","body":"## Overview\n\nAuthorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.\n\n## Affected\n\n- `revive_adserver <= 5.5.2`\n- `revive_adserver >= 6.0.0, <= 6.0.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}