Junglewise Threat Intelligence

CVE-2026-57401: Brainstorm Force SureDash path traversal arbitrary file deletion

CVE-2026-57401 · Severity: critical · CVSS 9.9 · Published 2026-07-13

Technologies: Brainstorm Force SureDash. Vendors: Brainstorm Force.

Executive brief

SureDash, a WordPress plugin used for client dashboards and portal management, contains a critical security flaw. An attacker with basic user permissions can exploit this vulnerability to delete important files from the web server. This could lead to a complete website failure, loss of data, or the removal of security configurations, effectively taking the business's online presence offline.

Technical details

A path traversal vulnerability (CWE-22) exists in the Brainstorm Force SureDash plugin for WordPress due to improper limitation of pathnames to a restricted directory. An authenticated attacker with low-level privileges can provide manipulated file paths to trigger arbitrary file deletion on the server. This can be used to delete critical system or application files, potentially leading to a denial-of-service (DoS) or bypassing security controls by removing configuration files. The vulnerability is resolved in version 1.8.1.

Affected products

  • Brainstorm Force SureDash <= 1.8.0

Timeline

  • 2026-04-28: disclosed: Reported by hhhai via Patchstack
  • 2026-07-08: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • patched: Fixed in version 1.8.1

References

Related threats