Unrestricted File Upload Vulnerability in Brave CMS by Ajax30
CVE-2026-35047
9.3CRITICAL
What is CVE-2026-35047?
Brave CMS, an open-source content management system, is vulnerable to an unrestricted file upload issue within its CKEditor endpoint. This flaw allows attackers to upload arbitrary files, including malicious executable scripts. Exploiting this vulnerability could lead to remote code execution on the server, potentially resulting in full system compromise, unauthorized access to sensitive data, or service disruptions. Users of Brave CMS versions prior to 2.0.6 are particularly at risk. The vulnerability has been addressed in the 2.0.6 update.
Affected Version(s)
BraveCMS-2.0 < 2.0.6
