CVE-2026-35183Disclosure(ajax30 / bravecms)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located in app/Http/Controllers/Dashboard/ArticleController.php within the deleteImage method. The endpoint accepts a filename from the URL but does not verify ownership. This allows an authenticated user with edit permissions to delete images attached to articles owned by other users. This vulnerability is fixed in 2.0.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bravecms

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
bravecms

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-06: 2Technical Details · 2026-04-06: 204-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35183 Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located … https://www.cve.org/CVERecord?id=CVE-2026-35183 ----- Traducción: CVE-2026-35183 Bra… http://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE-2026-35183 in Brave CMS, detailing an IDOR flaw in the article image deletion feature and providing a link to the CVE record.

    0000037
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35183 Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located … https://www.cve.org/CVERecord?id=CVE-2026-35183

    Post summary

    CVE-2026-35183 discloses an IDOR weakness in Brave CMS’s article image deletion before version 2.0.6, with the issue documented on the official CVE record.

    00000170
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appajax30bravecms---

Explore more