CVE-2026-77116: Unknown Brave
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.
Affected products
- Unknown Brave: before 0.8.6 (fixed in 0.8.6)
Published 2026-08-23. Last modified 2026-08-26.