Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to change account roles and promote themselves to Super Admin. This vulnerability is fixed in 2.0.6.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ajax30
Ajax30 bravecms-2.0 |
|
| Vendors & Products |
Ajax30
Ajax30 bravecms-2.0 |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to change account roles and promote themselves to Super Admin. This vulnerability is fixed in 2.0.6. | |
| Title | Missing Authorization Privilege Escalation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-06T19:10:28.850Z
Updated: 2026-04-07T14:04:00.456Z
Reserved: 2026-04-01T17:26:21.133Z
Link: CVE-2026-35182
Updated: 2026-04-07T14:03:52.166Z
Status : Undergoing Analysis
Published: 2026-04-06T20:16:26.553
Modified: 2026-04-07T15:17:42.810
Link: CVE-2026-35182
No data.