CVE-2026-35047Disclosure(ajax30 / bravecms)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on the server, potentially resulting in full system compromise, data exfiltration, or service disruption. All users running affected versions of BraveCMS are impacted. This vulnerability is fixed in 2.0.6.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bravecms

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
bravecms

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-06: 2PoC Mentioned / Linked · 2026-04-06: 1Technical Details · 2026-04-06: 204-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35047 Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, includ… https://www.cve.org/CVERecord?id=CVE-2026-35047

    Post summary

    The text announces an unrestricted file upload vulnerability in Brave CMS prior to 2.0.6, providing technical details but no evidence of exploitation, PoC, or remediation.

    00000102
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35047: Brave CMS has Unrestricted File ... CKEditor file upload bypass = instant shell access with zero auth required - classic WYSIWYG editor fail that screams m... https://zerodaysignal.com/vulnerability/CVE-2026-35047 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-35047, highlighting an unrestricted CKEditor file‑upload bug in Brave CMS that permits shell access with no authentication, but it does not detail patches or active exploitation evidence.

    0000078
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appajax30bravecms---

Explore more