rootpwn

high · CVSS v3 6.5 · CVSS v4 7.1 · EPSS 0.00306

CVE-2026-105129

LaraDashboard before 1.4.8 contains an authorization flaw that allows users with only settings.view permission to read sensitive secrets via

Overview

LaraDashboard before 1.4.8 contains an authorization flaw that allows users with only settings.view permission to read sensitive secrets via the settings API. This exposes AI provider keys, mail credentials, passwords, and tokens to any authenticated user. The vulnerability can be exploited by any user who has logged in.

Description

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

Impact

Confidentiality is compromised as attackers can retrieve plaintext secrets. Integrity may be affected if secrets are used to modify system behavior. Availability is not directly impacted. Administrators and developers of LaraDashboard installations are the primary defenders.

Remediation

Apply the latest patch (1.4.8 or later) that corrects the authorization check. If patching is delayed, restrict the settings API to users with higher privileges (e.g., settings.manage) and audit current permissions. Monitor API access logs for unusual activity.

Risk context

The vulnerability has a high severity rating (CVSS v3 6.5, v4 7.1) but a low EPSS of 0.00306, indicating a low probability of exploitation. Nonetheless, the potential impact warrants prompt remediation.

Affected products

  • LaraDashboard

Scores

Severity
high
CVSS v2
6.8
CVSS v3
6.5
CVSS v4
7.1
EPSS
0.00306

authorization settings API secrets exposure LaraDashboard high severity confidentiality breach

← All CVEs