CVE-2026-77116Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-23); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-23: 2Mentions · 2026-08-26: 1Mentions · 2026-08-27: 1Technical Details · 2026-08-23: 2Technical Details · 2026-08-26: 108-2308-2608-27
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-232
Disclosure2
2026-08-261
Disclosure1
2026-08-271
Disclosure1
Full discourse4 posts
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    🚨 Falla de acceso en plugin de WordPress expone contenido restringido de popups a usuarios básicos CVE-2026-77116 permite que suscriptores y clientes de tiendas lean información de ventanas emergentes sin autorización en sitios que usan… ¿Qué opinan? https://ciberseguridadlatam.com/falla-de-acceso-en-plugin-de-wordpress-expone-contenido/?utm_source=x&utm_medium=social&utm_campaign=falla-de-acceso-en-plugin-de&utm_content=post https://t.co/fh9tG2Y6nz

    Post summary

    The tweet reports CVE-2026-77116, highlighting a WordPress plugin flaw that allows basic users to access restricted popup content; it offers no evidence of exploitation or remediation details.

    03160922
    22.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-77116 Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer i… https://www.cve.org/CVERecord?id=CVE-2026-77116

    Post summary

    The post announces CVE‑2026‑77116, a broken access control flaw in the WordPress plugin Brave Popup Builder (up to v0.8.5) that allows any authenticated user to exploit the issue.

    000111.4K
    58.0K followersView on X
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    CVE-2026-77116: un usuario registrado en un sitio con Brave Popup Builder (v0.8.5 o menor) lee popups restringidos cambiando un número en la URL. Sin parche aún. México y Argentina lideran e-commerce con ofertas segmentadas. ¿Cuántas filtran códigos VIP? https://ciberseguridadlatam.com/falla-de-acceso-en-plugin-de-wordpress-expone-contenido/ https://t.co/gWjI5YrQV9

    Post summary

    The notice discloses CVE‑2026‑77116 in Brave Popup Builder, detailing how registered users can bypass restrictions by altering a URL parameter; no patch, exploit code, or wild‑world activity is reported.

    00001647
    22.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-77116 Broken Access Control in Brave Popup Builder Versions Through 0.8.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-77116

    Post summary

    The text announces CVE‑2026‑77116, describing a broken access control flaw in Brave Popup Builder versions up to 0.8.5, and provides a link to a vulnerability details page, without any PoC or exploit information.

    00000143
    4.1K followersView on X

Explore more