CVE-2026-35047 Details
Description
Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on the server, potentially resulting in full system compromise, data exfiltration, or service disruption. All users running affected versions of BraveCMS are impacted. This vulnerability is fixed in 2.0.6.
A vulnerability allowing unrestricted file uploads has been identified in Brave CMS versions prior to 2.0.6. This issue arises in the CKEditor endpoint, where attackers can upload arbitrary files, including executable scripts. Such uploads may lead to remote code execution on the server, potentially causing a full system compromise, data exfiltration, or service disruption.
Users are advised to upgrade to Brave CMS version 2.0.6 or later. If an immediate upgrade is not possible, access to the CKEditor upload endpoint should be restricted, strict server-side file validation should be enforced, execution of uploaded files via server configuration should be disabled, and suspicious uploaded files should be monitored and removed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ajax30 bravecms | >= 2.0.0, < 2.0.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | Initial Analysis | [email protected] |
| Apr 6, 2026 | New CVE Received | [email protected] |