CVE-2026-35182
EUVD-2026-1945806.04.2026, 20:16
Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to change account roles and promote themselves to Super Admin. This vulnerability is fixed in 2.0.6.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ajax30 | bravecms | 2.0.0 ≤ 𝑥 < 2.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration