OVERVIEW CVE-2026-35183 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Brave CMS versions prior to 2.0.6. The flaw exists in the article image deletion feature within the ArticleController.php file, where the deleteImage method fails to verify image ownership before processing deletion requests. SEVERITY This vulnerability carries a CVSS v3.1 severity rating of 5.4 (Medium) with a network-based attack vector requiring low complexity and low privileges. The impact is limited to integrity and availability concerns, as an authenticated user with edit permissions can delete images associated with articles owned by other users, resulting in minor data loss or service disruption. The FAUCET Risk Score of 41.0/100 indicates moderate organizational risk. EXPLOITATION STATUS There is currently no evidence of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog, the CVE Hot List is inactive, and the EPSS score of 0.00034 suggests minimal real-world exploitation activity compared to other published vulnerabilities. However, organizations running Brave CMS versions before 2.0.6 should prioritize upgrading to patch this vulnerability and prevent potential unauthorized image deletion incidents.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.6CPE matchmatch criteria | cpe:2.3:a:ajax30:bravecms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.