PT-2026-30715 · Brave Cms · Brave Cms

Para213

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-35183

CVSS v3.1

7.1

High

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Brave CMS versions prior to 2.0.6
Description A flaw exists in the article image deletion feature of Brave CMS, specifically within the deleteImage method in app/Http/Controllers/Dashboard/ArticleController.php. The affected endpoint does not verify ownership of the image file received from the URL, allowing an authenticated user with edit permissions to delete images associated with articles owned by other users. This is an Insecure Direct Object Reference (IDOR) issue.
Recommendations Update to version 2.0.6 or later.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-35183

Affected Products

Brave Cms