Unrestricted File Upload Vulnerability in Brave CMS by Ajax30
CVE-2026-35047

9.3CRITICAL

Key Information:

Vendor

Ajax30

Vendor
CVE Published:
6 April 2026

What is CVE-2026-35047?

Brave CMS, an open-source content management system, is vulnerable to an unrestricted file upload issue within its CKEditor endpoint. This flaw allows attackers to upload arbitrary files, including malicious executable scripts. Exploiting this vulnerability could lead to remote code execution on the server, potentially resulting in full system compromise, unauthorized access to sensitive data, or service disruptions. Users of Brave CMS versions prior to 2.0.6 are particularly at risk. The vulnerability has been addressed in the 2.0.6 update.

Affected Version(s)

BraveCMS-2.0 < 2.0.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.