PT-2026-30715 · Brave Cms · Brave Cms

·

CVE-2026-35183

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Brave CMS versions prior to 2.0.6
Description A flaw exists in the article image deletion feature of Brave CMS, specifically within the deleteImage method in app/Http/Controllers/Dashboard/ArticleController.php. The affected endpoint does not verify ownership of the image file received from the URL, allowing an authenticated user with edit permissions to delete images associated with articles owned by other users. This is an Insecure Direct Object Reference (IDOR) issue.
Recommendations Update to version 2.0.6 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35183

Affected Products

Brave Cms