high · CVSS v3 7.2 · CVSS v4 8.6 · EPSS 0.00493
CVE-2026-105126
LaraDashboard versions before 1.4.8 have a privilege escalation flaw that lets authenticated Admin users gain Superadmin rights by editing o
Overview
LaraDashboard versions before 1.4.8 have a privilege escalation flaw that lets authenticated Admin users gain Superadmin rights by editing or renaming roles. This allows attackers to access core upgrade and module installation functions, potentially leading to code execution. The vulnerability is exploitable by users with role.edit permissions.
Description
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
Impact
Confidentiality, Integrity, and Availability are at risk for organizations running vulnerable LaraDashboard installations. Admin users can elevate privileges to Superadmin, enabling unauthorized code execution and system compromise. Defenders should treat this as a high-impact privilege escalation threat.
Remediation
Apply the official patch to upgrade to version 1.4.8 or later. If patching is not immediately possible, restrict role.edit permissions to trusted users, disable role renaming features, and enforce least privilege on role management. Monitor for unauthorized role changes and audit logs.
Risk context
Severity is high with CVSS v3 7.2 and v4 8.6, but EPSS 0.00493 indicates low probability of exploitation in the wild. Nonetheless, the potential impact warrants prompt patching or mitigation.
Affected products
- LaraDashboard
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 7.2
- CVSS v4
- 8.6
- EPSS
- 0.00493