PT-2026-36689 · Eyeo · Adblock Plus

Drxyj

·

Published

2026-05-03

·

Updated

2026-05-03

·

CVE-2026-7686

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions eyeo Adblock Plus versions prior to 4.36.3
Description Improper access controls exist in the Legacy Premium Activation component within the postMessage() function of the premium.preload.js file. This allows remote exploitation through manipulation, though the affected code path is part of a deprecated activation flow. The licensing server issues short-lived trial licenses (approximately 24 hours) for any submitted userId, which expire upon the next validation if no valid subscription is found.
Recommendations Upgrade the affected component to a version later than 4.36.2.

Exploit

Fix

Incorrect Privilege Assignment

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7686

Affected Products

Adblock Plus