CVE-2026-35183 | Ajax30 BraveCMS up to 2.0.5 Endpoint ArticleController.php deleteImage authorization (EUVD-2026-19460)
A vulnerability was found in Ajax30 BraveCMS up to 2.0.5 and classified as problematic. Impacted is the function deleteImage of the file app/Http/Controllers/Dashboard/ArticleController.php of the component Endpoint. Such manipulation leads to authorization bypass.
This vulnerability is documented as CVE-2026-35183. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.