Home

Description

A vulnerability was found in eyeo Adblock Plus up to 4.36.2 on Chrome. Affected by this vulnerability is the function postMessage of the file premium.preload.js of the component Legacy Premium Activation. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been made public and could be used. Upgrading the affected component is recommended. The vendor provides additional details: "The affected code path is a legacy Premium activation flow that has been deprecated. eyeo has already migrated to a new user account-based licensing system. The exploit does not grant permanent Premium access. The licensing server issues a short-lived trial license (valid for approximately 24 hours) for any submitted userId. On the next license check, the server validates against a real subscription and the trial expires if no valid subscription is found. The researcher's claim of permanently unlocking all Premium features is therefore incorrect. (...) The old flow has been present for years and has not been weaponized at scale to our knowledge. The risk to eyeo and to users is minimal."

PUBLISHED Reserved 2026-05-02 | Published 2026-05-03 | Updated 2026-05-03 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
MEDIUM: 5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
5.0AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C

Problem types

Improper Access Controls

Incorrect Privilege Assignment

Product status

4.36.0
affected

4.36.1
affected

4.36.2
affected

Timeline

2026-05-02:Advisory disclosed
2026-05-02:VulDB entry created
2026-05-02:VulDB entry last update

Credits

DRXYJ (VulDB User) reporter

VulDB CNA Team coordinator

References

vuldb.com/vuln/360856 (VDB-360856 | eyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access control) vdb-entry technical-description

vuldb.com/vuln/360856/cti (VDB-360856 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/submit/793551 (Submit #793551 | Eyeo GmbH Adblock Plus 4.36.2 Privilege Escalation) third-party-advisory

github.com/xryj920/CVE/blob/main/adblock_plus_CVE_report.md exploit

adblockplus.org/en/download patch

cve.org (CVE-2026-7686)

nvd.nist.gov (CVE-2026-7686)

Download JSON