Back to all advisories

Tag: Privilege Escalation

1 advisory tagged with "Privilege Escalation".

CVE-2026-35182 High

Missing Authorization Privilege Escalation

BraveCMS 2.0.0 ships with a missing authorization check on the user-role update endpoint, allowing any authenticated low-privileged user to promote their own account to Super Admin by sending a single crafted POST request.

BraveCMS

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →