rootpwn

high · CVSS v3 7.2 · CVSS v4 8.6 · EPSS 0.00493

CVE-2026-105126

LaraDashboard versions before 1.4.8 have a privilege escalation flaw that lets authenticated Admin users gain Superadmin rights by editing o

Overview

LaraDashboard versions before 1.4.8 have a privilege escalation flaw that lets authenticated Admin users gain Superadmin rights by editing or renaming roles. This allows attackers to access core upgrade and module installation functions, potentially leading to code execution. The vulnerability is exploitable by users with role.edit permissions.

Description

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.

Impact

Confidentiality, Integrity, and Availability are at risk for organizations running vulnerable LaraDashboard installations. Admin users can elevate privileges to Superadmin, enabling unauthorized code execution and system compromise. Defenders should treat this as a high-impact privilege escalation threat.

Remediation

Apply the official patch to upgrade to version 1.4.8 or later. If patching is not immediately possible, restrict role.edit permissions to trusted users, disable role renaming features, and enforce least privilege on role management. Monitor for unauthorized role changes and audit logs.

Risk context

Severity is high with CVSS v3 7.2 and v4 8.6, but EPSS 0.00493 indicates low probability of exploitation in the wild. Nonetheless, the potential impact warrants prompt patching or mitigation.

Affected products

  • LaraDashboard

Scores

Severity
high
CVSS v2
8.3
CVSS v3
7.2
CVSS v4
8.6
EPSS
0.00493

privilege-escalation role-management admin code-execution LaraDashboard high-severity

← All CVEs