Search

Find a vulnerability

Search criteria

    30 vulnerabilities by laradashboard

    CVE-2026-105130 (GCVE-0-2026-105130)

    Vulnerability from nvd – Published: 2026-10-03 23:40 – Updated: 2026-10-05 16:14
    VLAI
    Title
    LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit
    Summary
    LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 16:11 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 1.4.0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105130",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T16:11:27.294260Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T16:14:41.623Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-gw6g-9wx9-3fpj"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "1.4.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:02.301Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-gw6g-9wx9-3fpj)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-gw6g-9wx9-3fpj"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Auth/RegisterController.php#L175-L188"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/Auth/RegistrationGuardService.php#L77-L105"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/343"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/1bc7b7e2d32dd0bbee8f39a7ed8a3316ae657d50"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-1.4.0-before-1.4.8-race-condition-bypasses-per-ip-registration-limit"
            }
          ],
          "title": "LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105130",
        "datePublished": "2026-10-03T23:40:02.301Z",
        "dateReserved": "2026-10-03T12:05:26.756Z",
        "dateUpdated": "2026-10-05T16:14:41.623Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105129 (GCVE-0-2026-105129)

    Vulnerability from nvd – Published: 2026-10-03 23:40 – Updated: 2026-10-06 16:51
    VLAI
    Title
    LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API
    Summary
    LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-06 16:51 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105129",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-06T16:51:41.895296Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-06T16:51:50.349Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:01.650Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-xgmw-7ppx-v7hq)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xgmw-7ppx-v7hq"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/SettingController.php#L23-L50"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResource.php#L17-L26"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#L15-L34"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/340"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2dbe3"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105129",
        "datePublished": "2026-10-03T23:40:01.650Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-06T16:51:50.349Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105128 (GCVE-0-2026-105128)

    Vulnerability from nvd – Published: 2026-10-03 23:40 – Updated: 2026-10-05 14:08
    VLAI
    Title
    LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url
    Summary
    LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 14:08 UTC
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105128",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T14:08:38.308534Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T14:08:45.132Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:01.065Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-j2vp-w788-8fcf)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L142"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L159"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/resources/js/lara-builder/core/LaraBuilder.jsx#L762"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/341"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/c08da68236267afc0c0073598f66fadbc1b53b66"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-open-redirect-via-email-template-builder-redirect-url"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105128",
        "datePublished": "2026-10-03T23:40:01.065Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-05T14:08:45.132Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105127 (GCVE-0-2026-105127)

    Vulnerability from nvd – Published: 2026-10-03 23:40 – Updated: 2026-10-05 15:42
    VLAI
    Title
    LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints
    Summary
    LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 15:42 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 1.4.2 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105127",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T15:42:13.004909Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T15:42:38.296Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "1.4.2",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:00.470Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-v36p-8578-8gch)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch"
            },
            {
              "name": "GitHub Security Advisory (GHSA-5hq2-r2f3-9vp9)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-5hq2-r2f3-9vp9"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ForgotPasswordRequest.php#L22-L27"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ResetPasswordRequest.php#L23-L30"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailVerificationService.php#L95-L114"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailDomainCheckService.php#L128"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/339"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/8babc803066a74c628fa012928fb1e6591411eba"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-1.4.2-before-1.4.8-resource-exhaustion-via-password-recovery-endpoints"
            }
          ],
          "title": "LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105127",
        "datePublished": "2026-10-03T23:40:00.470Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-05T15:42:38.296Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105126 (GCVE-0-2026-105126)

    Vulnerability from nvd – Published: 2026-10-03 23:39 – Updated: 2026-10-05 20:29
    VLAI
    Title
    LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
    Summary
    LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 20:06 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105126",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T20:06:24.912925Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T20:29:34.353Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:39:59.775Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-555v-6rfr-r969)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-555v-6rfr-r969"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L144"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L180"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/RolePolicy.php#L39-L50"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/CoreUpgrade/UploadRequest.php#L23"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/344"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/286f150e4d0c924ec1ce7eb256b2326e871e9517"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-privilege-escalation-via-superadmin-role-tampering"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105126",
        "datePublished": "2026-10-03T23:39:59.775Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-05T20:29:34.353Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105125 (GCVE-0-2026-105125)

    Vulnerability from nvd – Published: 2026-10-03 23:39 – Updated: 2026-10-05 16:16
    VLAI
    Title
    LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
    Summary
    LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 16:16 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105125",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T16:16:34.646467Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T16:16:44.140Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:39:59.168Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-43jp-66c9-7cgh)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c9-7cgh"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.php#L36-L46"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/350"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae8687247540d73a21505e"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-via-api-translations-lang-endpoint"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105125",
        "datePublished": "2026-10-03T23:39:59.168Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-05T16:16:44.140Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90933 (GCVE-0-2026-90933)

    Vulnerability from nvd – Published: 2026-09-14 12:48 – Updated: 2026-09-14 13:38
    VLAI
    Title
    laradashboard through 1.2.2 Missing Authorization via License API
    Summary
    laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store, and POST /api/admin/licenses/remove endpoints to disclose confidential license keys, inject attacker-controlled values, or delete stored licenses entirely.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 13:38 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , ≤ 1.2.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-90933",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T13:38:11.865968Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T13:38:29.284Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4m5-rrc4-5qv6"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThanOrEqual": "1.2.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "1.2.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "EQSTLab"
            }
          ],
          "datePublic": "2026-08-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store, and POST /api/admin/licenses/remove endpoints to disclose confidential license keys, inject attacker-controlled values, or delete stored licenses entirely."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T12:48:28.438Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-j4m5-rrc4-5qv6)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4m5-rrc4-5qv6"
            },
            {
              "name": "VulnCheck Advisory: laradashboard through 1.2.2 Missing Authorization via License API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-through-1.2.2-missing-authorization-via-license-api"
            }
          ],
          "title": "laradashboard through 1.2.2 Missing Authorization via License API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-90933",
        "datePublished": "2026-09-14T12:48:28.438Z",
        "dateReserved": "2026-09-14T11:33:51.886Z",
        "dateUpdated": "2026-09-14T13:38:29.284Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90932 (GCVE-0-2026-90932)

    Vulnerability from nvd – Published: 2026-09-14 12:48 – Updated: 2026-09-16 14:59
    VLAI
    Title
    LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE
    Summary
    LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation, without applying basename(), and without verifying that the resolved path remains inside storage/app/core-backups; the corresponding form requests only validate the value as a bounded string. An authenticated user holding only the delegated settings.edit permission (not Superadmin) can supply ../ traversal sequences to delete arbitrary files reachable on the host filesystem, including outside the application tree, or to restore a ZIP archive from an arbitrary on-disk location, writing arbitrary files into the application directories and achieving remote code execution. Note: the advisory states the vulnerable concatenation was introduced in the v0.9.7 release line. No patched version was available at the time of publication.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 14:59 UTC
    CWE
    • CWE-73 - External Control of File Name or Path
    References
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0.9.2 , ≤ 1.4.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-90932",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T14:59:11.087491Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T14:59:56.354Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-g48h-h5pc-396j"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThanOrEqual": "1.4.2",
                  "status": "affected",
                  "version": "0.9.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "1.4.2",
                      "versionStartIncluding": "0.9.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "capivara-research"
            }
          ],
          "datePublic": "2026-08-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation, without applying basename(), and without verifying that the resolved path remains inside storage/app/core-backups; the corresponding form requests only validate the value as a bounded string. An authenticated user holding only the delegated settings.edit permission (not Superadmin) can supply ../ traversal sequences to delete arbitrary files reachable on the host filesystem, including outside the application tree, or to restore a ZIP archive from an arbitrary on-disk location, writing arbitrary files into the application directories and achieving remote code execution. Note: the advisory states the vulnerable concatenation was introduced in the v0.9.7 release line. No patched version was available at the time of publication."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T12:48:27.487Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-g48h-h5pc-396j)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-g48h-h5pc-396j"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-0.9.2-through-1.2.2-path-traversal-rce"
            }
          ],
          "title": "LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-90932",
        "datePublished": "2026-09-14T12:48:27.487Z",
        "dateReserved": "2026-09-14T11:33:51.886Z",
        "dateUpdated": "2026-09-16T14:59:56.354Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90931 (GCVE-0-2026-90931)

    Vulnerability from nvd – Published: 2026-09-14 12:48 – Updated: 2026-09-14 20:26
    VLAI
    Title
    LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload
    Summary
    LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application origin, the embedded JavaScript executes in the dashboard context, enabling session hijacking and administrative account takeover.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 20:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0.9.0 , ≤ 1.4.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-90931",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T20:26:39.704798Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T20:26:47.225Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-9gxw-qpx8-x9c7"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThanOrEqual": "1.4.2",
                  "status": "affected",
                  "version": "0.9.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "1.4.2",
                      "versionStartIncluding": "0.9.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "capivara-research"
            }
          ],
          "datePublic": "2026-08-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application origin, the embedded JavaScript executes in the dashboard context, enabling session hijacking and administrative account takeover."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T12:48:26.835Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-9gxw-qpx8-x9c7)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-9gxw-qpx8-x9c7"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-0.9.0-through-1.2.2-stored-xss-via-svg-upload"
            }
          ],
          "title": "LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-90931",
        "datePublished": "2026-09-14T12:48:26.835Z",
        "dateReserved": "2026-09-14T11:33:51.886Z",
        "dateUpdated": "2026-09-14T20:26:47.225Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87821 (GCVE-0-2026-87821)

    Vulnerability from nvd – Published: 2026-09-09 11:21 – Updated: 2026-09-09 12:08
    VLAI
    Title
    Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch
    Summary
    Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 12:05 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0.9.2 , < 1.3.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-05 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87821",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T12:05:47.404761Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-09T12:08:03.123Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4xqv-4c27-6c4j"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/laradashboard/laradashboard",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "repo": "https://github.com/laradashboard/laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.2",
                  "status": "affected",
                  "version": "0.9.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.2",
                      "versionStartIncluding": "0.9.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T11:21:06.740Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-4xqv-4c27-6c4j)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4xqv-4c27-6c4j"
            },
            {
              "name": "GitHub Security Advisory (GHSA-f36j-h77g-6wj8)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-f36j-h77g-6wj8"
            },
            {
              "name": "Fix commit adding SafeUrlValidator",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2"
            },
            {
              "name": "Unguarded server-side fetch at v1.3.1",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Services/Builder/MarkdownFetchService.php"
            },
            {
              "name": "Same unguarded fetch at v0.9.2, the first release carrying the service",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v0.9.2/app/Services/Builder/MarkdownFetchService.php"
            },
            {
              "name": "Controller with no authorization check at v1.3.1",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Controllers/Api/Builder/MarkdownController.php"
            },
            {
              "name": "Host allowlist introduced in v1.3.2",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.2/app/Support/Security/SafeUrlValidator.php"
            },
            {
              "name": "laradashboard v1.3.2 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-0.9.2-through-1.3.1-server-side-request-forgery-in-builder-markdown-fetch"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-87821",
        "datePublished": "2026-09-09T11:21:06.740Z",
        "dateReserved": "2026-09-09T10:32:34.110Z",
        "dateUpdated": "2026-09-09T12:08:03.123Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86438 (GCVE-0-2026-86438)

    Vulnerability from nvd – Published: 2026-09-07 22:01 – Updated: 2026-09-10 15:03
    VLAI
    Title
    Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
    Summary
    Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 14:24 UTC
    CWE
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.3.2 (semver)
    Unaffected: 1.3.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-05 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86438",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T14:24:52.278505Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:03:37.121Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.3.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T22:01:49.499Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-4x9p-vg5m-vr6p)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4x9p-vg5m-vr6p"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Livewire/Marketplace/MarketplaceModuleBrowser.php#L76-L120"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Policies/ModulePolicy.php#L32-L38"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2"
            },
            {
              "name": "laradashboard v1.3.2 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-missing-authorization-in-marketplace-module-install-action"
            }
          ],
          "title": "Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86438",
        "datePublished": "2026-09-07T22:01:49.499Z",
        "dateReserved": "2026-09-07T12:34:31.457Z",
        "dateUpdated": "2026-09-10T15:03:37.121Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86437 (GCVE-0-2026-86437)

    Vulnerability from nvd – Published: 2026-09-07 22:01 – Updated: 2026-09-08 12:36
    VLAI
    Title
    Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload
    Summary
    Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 12:35 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.3.2 (semver)
    Unaffected: 1.3.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-05 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86437",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T12:35:37.962525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T12:36:05.467Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xv98-x5h7-4g7v"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.3.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T22:01:48.812Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-xv98-x5h7-4g7v)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xv98-x5h7-4g7v"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Requests/CoreUpgrade/UploadRequest.php#L15-L18"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Policies/SettingPolicy.php#L47-L50"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Services/CoreUpgradeService.php#L543-L577"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2"
            },
            {
              "name": "laradashboard v1.3.2 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-incorrect-authorization-in-core-upgrade-archive-upload"
            }
          ],
          "title": "Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86437",
        "datePublished": "2026-09-07T22:01:48.812Z",
        "dateReserved": "2026-09-07T12:34:31.457Z",
        "dateUpdated": "2026-09-08T12:36:05.467Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86436 (GCVE-0-2026-86436)

    Vulnerability from nvd – Published: 2026-09-07 22:01 – Updated: 2026-09-09 14:47
    VLAI
    Title
    Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints
    Summary
    Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 14:47 UTC
    CWE
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.3.2 (semver)
    Unaffected: 1.3.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-04 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86436",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T14:47:25.750770Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-09T14:47:59.009Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4mm-xcgj-vpvv"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.3.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T22:01:48.106Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-j4mm-xcgj-vpvv)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4mm-xcgj-vpvv"
            },
            {
              "name": "GitHub Security Advisory (GHSA-hp3f-j9w2-5rqg)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-hp3f-j9w2-5rqg"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Controllers/Backend/PostController.php#L727-L741"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/routes/web.php#L243-L244"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2"
            },
            {
              "name": "laradashboard v1.3.2 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-missing-authorization-in-post-builder-media-upload-endpoints"
            }
          ],
          "title": "Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86436",
        "datePublished": "2026-09-07T22:01:48.106Z",
        "dateReserved": "2026-09-07T12:34:31.457Z",
        "dateUpdated": "2026-09-09T14:47:59.009Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86184 (GCVE-0-2026-86184)

    Vulnerability from nvd – Published: 2026-09-05 11:38 – Updated: 2026-09-18 17:23
    VLAI
    Title
    Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route
    Summary
    Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:07 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.3.0 (semver)
    Unaffected: 1.3.0 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-03 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:07:00.632835Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:23:11.175Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.3.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-05T11:38:00.626Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-wj35-4h53-phfp)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-wj35-4h53-phfp"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/50986e4ac58c883dd8f064cf32be3e2a87c11b24"
            },
            {
              "name": "ScreenshotGeneratorLoginController::login() at v1.2.2",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.2.2/app/Http/Controllers/Backend/Auth/ScreenshotGeneratorLoginController.php"
            },
            {
              "name": "Lara Dashboard v1.3.0 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.0"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.0-missing-authentication-in-screenshot-login-route"
            }
          ],
          "title": "Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86184",
        "datePublished": "2026-09-05T11:38:00.626Z",
        "dateReserved": "2026-09-05T11:16:13.582Z",
        "dateUpdated": "2026-09-18T17:23:11.175Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-66509 (GCVE-0-2025-66509)

    Vulnerability from nvd – Published: 2025-12-04 22:10 – Updated: 2025-12-05 15:23
    VLAI
    Title
    LaraDashboard: 1-Click Pre-Auth RCE via Host Header + Module Installation Chain
    Summary
    LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-05 15:23 UTC
    CWE
    • CWE-284 - Improper Access Control
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-66509",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-05T15:23:50.205546Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-05T15:23:58.141Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c= 2.3.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator\u2019s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.9,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-04T22:10:26.848Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j9mm-c9cj-pc82",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j9mm-c9cj-pc82"
            },
            {
              "name": "https://github.com/laradashboard/laradashboard/commit/cc42f9cdf8e59bce794ee2d812a9709b1e6efa87",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/cc42f9cdf8e59bce794ee2d812a9709b1e6efa87"
            }
          ],
          "source": {
            "advisory": "GHSA-j9mm-c9cj-pc82",
            "discovery": "UNKNOWN"
          },
          "title": "LaraDashboard: 1-Click Pre-Auth RCE via Host Header + Module Installation Chain"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2025-66509",
        "datePublished": "2025-12-04T22:10:26.848Z",
        "dateReserved": "2025-12-03T15:12:22.978Z",
        "dateUpdated": "2025-12-05T15:23:58.141Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105130 (GCVE-0-2026-105130)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-05 16:14
    VLAI
    Title
    LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit
    Summary
    LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 16:11 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 1.4.0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105130",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T16:11:27.294260Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T16:14:41.623Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-gw6g-9wx9-3fpj"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "1.4.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:02.301Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-gw6g-9wx9-3fpj)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-gw6g-9wx9-3fpj"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Auth/RegisterController.php#L175-L188"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/Auth/RegistrationGuardService.php#L77-L105"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/343"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/1bc7b7e2d32dd0bbee8f39a7ed8a3316ae657d50"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-1.4.0-before-1.4.8-race-condition-bypasses-per-ip-registration-limit"
            }
          ],
          "title": "LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105130",
        "datePublished": "2026-10-03T23:40:02.301Z",
        "dateReserved": "2026-10-03T12:05:26.756Z",
        "dateUpdated": "2026-10-05T16:14:41.623Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105129 (GCVE-0-2026-105129)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-06 16:51
    VLAI
    Title
    LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API
    Summary
    LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-06 16:51 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105129",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-06T16:51:41.895296Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-06T16:51:50.349Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:01.650Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-xgmw-7ppx-v7hq)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xgmw-7ppx-v7hq"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/SettingController.php#L23-L50"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResource.php#L17-L26"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#L15-L34"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/340"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2dbe3"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105129",
        "datePublished": "2026-10-03T23:40:01.650Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-06T16:51:50.349Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105128 (GCVE-0-2026-105128)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-05 14:08
    VLAI
    Title
    LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url
    Summary
    LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 14:08 UTC
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105128",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T14:08:38.308534Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T14:08:45.132Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:01.065Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-j2vp-w788-8fcf)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L142"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L159"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/resources/js/lara-builder/core/LaraBuilder.jsx#L762"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/341"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/c08da68236267afc0c0073598f66fadbc1b53b66"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-open-redirect-via-email-template-builder-redirect-url"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105128",
        "datePublished": "2026-10-03T23:40:01.065Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-05T14:08:45.132Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105127 (GCVE-0-2026-105127)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-05 15:42
    VLAI
    Title
    LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints
    Summary
    LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 15:42 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 1.4.2 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105127",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T15:42:13.004909Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T15:42:38.296Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "1.4.2",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:00.470Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-v36p-8578-8gch)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch"
            },
            {
              "name": "GitHub Security Advisory (GHSA-5hq2-r2f3-9vp9)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-5hq2-r2f3-9vp9"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ForgotPasswordRequest.php#L22-L27"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ResetPasswordRequest.php#L23-L30"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailVerificationService.php#L95-L114"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailDomainCheckService.php#L128"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/339"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/8babc803066a74c628fa012928fb1e6591411eba"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-1.4.2-before-1.4.8-resource-exhaustion-via-password-recovery-endpoints"
            }
          ],
          "title": "LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105127",
        "datePublished": "2026-10-03T23:40:00.470Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-05T15:42:38.296Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105126 (GCVE-0-2026-105126)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:39 – Updated: 2026-10-05 20:29
    VLAI
    Title
    LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
    Summary
    LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 20:06 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105126",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T20:06:24.912925Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T20:29:34.353Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:39:59.775Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-555v-6rfr-r969)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-555v-6rfr-r969"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L144"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L180"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/RolePolicy.php#L39-L50"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/CoreUpgrade/UploadRequest.php#L23"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/344"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/286f150e4d0c924ec1ce7eb256b2326e871e9517"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-privilege-escalation-via-superadmin-role-tampering"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105126",
        "datePublished": "2026-10-03T23:39:59.775Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-05T20:29:34.353Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105125 (GCVE-0-2026-105125)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:39 – Updated: 2026-10-05 16:16
    VLAI
    Title
    LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
    Summary
    LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 16:16 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105125",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T16:16:34.646467Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T16:16:44.140Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:39:59.168Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-43jp-66c9-7cgh)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c9-7cgh"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.php#L36-L46"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/350"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae8687247540d73a21505e"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-via-api-translations-lang-endpoint"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105125",
        "datePublished": "2026-10-03T23:39:59.168Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-05T16:16:44.140Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90933 (GCVE-0-2026-90933)

    Vulnerability from cvelistv5 – Published: 2026-09-14 12:48 – Updated: 2026-09-14 13:38
    VLAI
    Title
    laradashboard through 1.2.2 Missing Authorization via License API
    Summary
    laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store, and POST /api/admin/licenses/remove endpoints to disclose confidential license keys, inject attacker-controlled values, or delete stored licenses entirely.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 13:38 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , ≤ 1.2.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-90933",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T13:38:11.865968Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T13:38:29.284Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4m5-rrc4-5qv6"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThanOrEqual": "1.2.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "1.2.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "EQSTLab"
            }
          ],
          "datePublic": "2026-08-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store, and POST /api/admin/licenses/remove endpoints to disclose confidential license keys, inject attacker-controlled values, or delete stored licenses entirely."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T12:48:28.438Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-j4m5-rrc4-5qv6)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4m5-rrc4-5qv6"
            },
            {
              "name": "VulnCheck Advisory: laradashboard through 1.2.2 Missing Authorization via License API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-through-1.2.2-missing-authorization-via-license-api"
            }
          ],
          "title": "laradashboard through 1.2.2 Missing Authorization via License API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-90933",
        "datePublished": "2026-09-14T12:48:28.438Z",
        "dateReserved": "2026-09-14T11:33:51.886Z",
        "dateUpdated": "2026-09-14T13:38:29.284Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90932 (GCVE-0-2026-90932)

    Vulnerability from cvelistv5 – Published: 2026-09-14 12:48 – Updated: 2026-09-16 14:59
    VLAI
    Title
    LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE
    Summary
    LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation, without applying basename(), and without verifying that the resolved path remains inside storage/app/core-backups; the corresponding form requests only validate the value as a bounded string. An authenticated user holding only the delegated settings.edit permission (not Superadmin) can supply ../ traversal sequences to delete arbitrary files reachable on the host filesystem, including outside the application tree, or to restore a ZIP archive from an arbitrary on-disk location, writing arbitrary files into the application directories and achieving remote code execution. Note: the advisory states the vulnerable concatenation was introduced in the v0.9.7 release line. No patched version was available at the time of publication.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 14:59 UTC
    CWE
    • CWE-73 - External Control of File Name or Path
    References
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0.9.2 , ≤ 1.4.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-90932",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T14:59:11.087491Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T14:59:56.354Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-g48h-h5pc-396j"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThanOrEqual": "1.4.2",
                  "status": "affected",
                  "version": "0.9.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "1.4.2",
                      "versionStartIncluding": "0.9.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "capivara-research"
            }
          ],
          "datePublic": "2026-08-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation, without applying basename(), and without verifying that the resolved path remains inside storage/app/core-backups; the corresponding form requests only validate the value as a bounded string. An authenticated user holding only the delegated settings.edit permission (not Superadmin) can supply ../ traversal sequences to delete arbitrary files reachable on the host filesystem, including outside the application tree, or to restore a ZIP archive from an arbitrary on-disk location, writing arbitrary files into the application directories and achieving remote code execution. Note: the advisory states the vulnerable concatenation was introduced in the v0.9.7 release line. No patched version was available at the time of publication."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T12:48:27.487Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-g48h-h5pc-396j)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-g48h-h5pc-396j"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-0.9.2-through-1.2.2-path-traversal-rce"
            }
          ],
          "title": "LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-90932",
        "datePublished": "2026-09-14T12:48:27.487Z",
        "dateReserved": "2026-09-14T11:33:51.886Z",
        "dateUpdated": "2026-09-16T14:59:56.354Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90931 (GCVE-0-2026-90931)

    Vulnerability from cvelistv5 – Published: 2026-09-14 12:48 – Updated: 2026-09-14 20:26
    VLAI
    Title
    LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload
    Summary
    LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application origin, the embedded JavaScript executes in the dashboard context, enabling session hijacking and administrative account takeover.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 20:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0.9.0 , ≤ 1.4.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-90931",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T20:26:39.704798Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T20:26:47.225Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-9gxw-qpx8-x9c7"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThanOrEqual": "1.4.2",
                  "status": "affected",
                  "version": "0.9.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "1.4.2",
                      "versionStartIncluding": "0.9.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "capivara-research"
            }
          ],
          "datePublic": "2026-08-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application origin, the embedded JavaScript executes in the dashboard context, enabling session hijacking and administrative account takeover."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T12:48:26.835Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-9gxw-qpx8-x9c7)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-9gxw-qpx8-x9c7"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-0.9.0-through-1.2.2-stored-xss-via-svg-upload"
            }
          ],
          "title": "LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-90931",
        "datePublished": "2026-09-14T12:48:26.835Z",
        "dateReserved": "2026-09-14T11:33:51.886Z",
        "dateUpdated": "2026-09-14T20:26:47.225Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87821 (GCVE-0-2026-87821)

    Vulnerability from cvelistv5 – Published: 2026-09-09 11:21 – Updated: 2026-09-09 12:08
    VLAI
    Title
    Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch
    Summary
    Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 12:05 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0.9.2 , < 1.3.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-05 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87821",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T12:05:47.404761Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-09T12:08:03.123Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4xqv-4c27-6c4j"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/laradashboard/laradashboard",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "repo": "https://github.com/laradashboard/laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.2",
                  "status": "affected",
                  "version": "0.9.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.2",
                      "versionStartIncluding": "0.9.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T11:21:06.740Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-4xqv-4c27-6c4j)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4xqv-4c27-6c4j"
            },
            {
              "name": "GitHub Security Advisory (GHSA-f36j-h77g-6wj8)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-f36j-h77g-6wj8"
            },
            {
              "name": "Fix commit adding SafeUrlValidator",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2"
            },
            {
              "name": "Unguarded server-side fetch at v1.3.1",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Services/Builder/MarkdownFetchService.php"
            },
            {
              "name": "Same unguarded fetch at v0.9.2, the first release carrying the service",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v0.9.2/app/Services/Builder/MarkdownFetchService.php"
            },
            {
              "name": "Controller with no authorization check at v1.3.1",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Controllers/Api/Builder/MarkdownController.php"
            },
            {
              "name": "Host allowlist introduced in v1.3.2",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.2/app/Support/Security/SafeUrlValidator.php"
            },
            {
              "name": "laradashboard v1.3.2 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-0.9.2-through-1.3.1-server-side-request-forgery-in-builder-markdown-fetch"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-87821",
        "datePublished": "2026-09-09T11:21:06.740Z",
        "dateReserved": "2026-09-09T10:32:34.110Z",
        "dateUpdated": "2026-09-09T12:08:03.123Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86438 (GCVE-0-2026-86438)

    Vulnerability from cvelistv5 – Published: 2026-09-07 22:01 – Updated: 2026-09-10 15:03
    VLAI
    Title
    Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
    Summary
    Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 14:24 UTC
    CWE
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.3.2 (semver)
    Unaffected: 1.3.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-05 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86438",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T14:24:52.278505Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:03:37.121Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.3.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T22:01:49.499Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-4x9p-vg5m-vr6p)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4x9p-vg5m-vr6p"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Livewire/Marketplace/MarketplaceModuleBrowser.php#L76-L120"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Policies/ModulePolicy.php#L32-L38"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2"
            },
            {
              "name": "laradashboard v1.3.2 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-missing-authorization-in-marketplace-module-install-action"
            }
          ],
          "title": "Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86438",
        "datePublished": "2026-09-07T22:01:49.499Z",
        "dateReserved": "2026-09-07T12:34:31.457Z",
        "dateUpdated": "2026-09-10T15:03:37.121Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86437 (GCVE-0-2026-86437)

    Vulnerability from cvelistv5 – Published: 2026-09-07 22:01 – Updated: 2026-09-08 12:36
    VLAI
    Title
    Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload
    Summary
    Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 12:35 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.3.2 (semver)
    Unaffected: 1.3.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-05 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86437",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T12:35:37.962525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T12:36:05.467Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xv98-x5h7-4g7v"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.3.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T22:01:48.812Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-xv98-x5h7-4g7v)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xv98-x5h7-4g7v"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Requests/CoreUpgrade/UploadRequest.php#L15-L18"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Policies/SettingPolicy.php#L47-L50"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Services/CoreUpgradeService.php#L543-L577"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2"
            },
            {
              "name": "laradashboard v1.3.2 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-incorrect-authorization-in-core-upgrade-archive-upload"
            }
          ],
          "title": "Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86437",
        "datePublished": "2026-09-07T22:01:48.812Z",
        "dateReserved": "2026-09-07T12:34:31.457Z",
        "dateUpdated": "2026-09-08T12:36:05.467Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86436 (GCVE-0-2026-86436)

    Vulnerability from cvelistv5 – Published: 2026-09-07 22:01 – Updated: 2026-09-09 14:47
    VLAI
    Title
    Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints
    Summary
    Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 14:47 UTC
    CWE
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.3.2 (semver)
    Unaffected: 1.3.2 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-04 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86436",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T14:47:25.750770Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-09T14:47:59.009Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4mm-xcgj-vpvv"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.3.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T22:01:48.106Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-j4mm-xcgj-vpvv)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4mm-xcgj-vpvv"
            },
            {
              "name": "GitHub Security Advisory (GHSA-hp3f-j9w2-5rqg)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-hp3f-j9w2-5rqg"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Controllers/Backend/PostController.php#L727-L741"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.3.1/routes/web.php#L243-L244"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2"
            },
            {
              "name": "laradashboard v1.3.2 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-missing-authorization-in-post-builder-media-upload-endpoints"
            }
          ],
          "title": "Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86436",
        "datePublished": "2026-09-07T22:01:48.106Z",
        "dateReserved": "2026-09-07T12:34:31.457Z",
        "dateUpdated": "2026-09-09T14:47:59.009Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86184 (GCVE-0-2026-86184)

    Vulnerability from cvelistv5 – Published: 2026-09-05 11:38 – Updated: 2026-09-18 17:23
    VLAI
    Title
    Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route
    Summary
    Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:07 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.3.0 (semver)
    Unaffected: 1.3.0 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-03 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:07:00.632835Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:23:11.175Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.3.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-05T11:38:00.626Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-wj35-4h53-phfp)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-wj35-4h53-phfp"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/50986e4ac58c883dd8f064cf32be3e2a87c11b24"
            },
            {
              "name": "ScreenshotGeneratorLoginController::login() at v1.2.2",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.2.2/app/Http/Controllers/Backend/Auth/ScreenshotGeneratorLoginController.php"
            },
            {
              "name": "Lara Dashboard v1.3.0 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.0"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.0-missing-authentication-in-screenshot-login-route"
            }
          ],
          "title": "Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86184",
        "datePublished": "2026-09-05T11:38:00.626Z",
        "dateReserved": "2026-09-05T11:16:13.582Z",
        "dateUpdated": "2026-09-18T17:23:11.175Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-66509 (GCVE-0-2025-66509)

    Vulnerability from cvelistv5 – Published: 2025-12-04 22:10 – Updated: 2025-12-05 15:23
    VLAI
    Title
    LaraDashboard: 1-Click Pre-Auth RCE via Host Header + Module Installation Chain
    Summary
    LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-05 15:23 UTC
    CWE
    • CWE-284 - Improper Access Control
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-66509",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-05T15:23:50.205546Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-05T15:23:58.141Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c= 2.3.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator\u2019s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.9,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-04T22:10:26.848Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j9mm-c9cj-pc82",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j9mm-c9cj-pc82"
            },
            {
              "name": "https://github.com/laradashboard/laradashboard/commit/cc42f9cdf8e59bce794ee2d812a9709b1e6efa87",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/cc42f9cdf8e59bce794ee2d812a9709b1e6efa87"
            }
          ],
          "source": {
            "advisory": "GHSA-j9mm-c9cj-pc82",
            "discovery": "UNKNOWN"
          },
          "title": "LaraDashboard: 1-Click Pre-Auth RCE via Host Header + Module Installation Chain"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2025-66509",
        "datePublished": "2025-12-04T22:10:26.848Z",
        "dateReserved": "2025-12-03T15:12:22.978Z",
        "dateUpdated": "2025-12-05T15:23:58.141Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }