CVE-2026-35047 is an unrestricted file upload vulnerability in Brave CMS versions prior to 2.0.6, specifically affecting the CKEditor endpoint. This flaw enables unauthenticated attackers to upload arbitrary files, including executable scripts, potentially leading to remote code execution and complete system compromise. All users operating vulnerable versions are affected until they upgrade to version 2.0.6 or later. The vulnerability carries a CVSS score of 9.8 (Critical) with a network-based attack vector requiring no authentication or user interaction, making it trivial to exploit. The potential impact is severe, with attackers capable of executing arbitrary code on the server, exfiltrating sensitive data, or disrupting service availability across all confidentiality, integrity, and availability dimensions. Current exploitation activity appears minimal. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains on the inactive Hot List, indicating no widespread active exploitation has been publicly reported. However, the moderate FAUCET Risk Score of 54.0 and relatively straightforward nature of the vulnerability warrant prompt patching, as exploit code could emerge opportunistically.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.6CPE matchmatch criteria | cpe:2.3:a:ajax30:bravecms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.