Home

Description

Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on the server, potentially resulting in full system compromise, data exfiltration, or service disruption. All users running affected versions of BraveCMS are impacted. This vulnerability is fixed in 2.0.6.

PUBLISHED Reserved 2026-03-31 | Published 2026-04-06 | Updated 2026-04-07 | Assigner GitHub_M




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-434: Unrestricted Upload of File with Dangerous Type

Product status

< 2.0.6
affected

References

github.com/...MS-2.0/security/advisories/GHSA-9rcc-w59j-965v

github.com/Ajax30/BraveCMS-2.0/pull/122

github.com/...ommit/058ee4ed7c2b39d540af8274024afcbc9532aa83

cve.org (CVE-2026-35047)

nvd.nist.gov (CVE-2026-35047)

Download JSON