high · CVSS v3 6.5 · CVSS v4 7.1 · EPSS 0.00306
CVE-2026-105129
LaraDashboard before 1.4.8 contains an authorization flaw that allows users with only settings.view permission to read sensitive secrets via
Overview
LaraDashboard before 1.4.8 contains an authorization flaw that allows users with only settings.view permission to read sensitive secrets via the settings API. This exposes AI provider keys, mail credentials, passwords, and tokens to any authenticated user. The vulnerability can be exploited by any user who has logged in.
Description
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
Impact
Confidentiality is compromised as attackers can retrieve plaintext secrets. Integrity may be affected if secrets are used to modify system behavior. Availability is not directly impacted. Administrators and developers of LaraDashboard installations are the primary defenders.
Remediation
Apply the latest patch (1.4.8 or later) that corrects the authorization check. If patching is delayed, restrict the settings API to users with higher privileges (e.g., settings.manage) and audit current permissions. Monitor API access logs for unusual activity.
Risk context
The vulnerability has a high severity rating (CVSS v3 6.5, v4 7.1) but a low EPSS of 0.00306, indicating a low probability of exploitation. Nonetheless, the potential impact warrants prompt remediation.
Affected products
- LaraDashboard
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 6.5
- CVSS v4
- 7.1
- EPSS
- 0.00306