medium · CVSS v3 3.7 · CVSS v4 6.3 · EPSS 0.00223
CVE-2026-105130
LaraDashboard versions 1.4.0 through 1.4.7 contain a race condition in the registration flow that lets attackers create accounts from a sing
Overview
LaraDashboard versions 1.4.0 through 1.4.7 contain a race condition in the registration flow that lets attackers create accounts from a single IP without hitting the daily limit. This bypasses anti‑automation controls and can lead to mass account creation. The flaw is triggered by concurrent registration requests.
Description
LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.
Impact
Confidentiality: attackers can create arbitrary user accounts, potentially gaining access to privileged resources. Integrity: the system's anti‑automation controls are subverted, allowing automated account creation. Availability: large numbers of accounts may strain resources. Defenders: administrators of LaraDashboard installations must patch or mitigate.
Remediation
Apply the official patch to upgrade to version 1.4.8 or later. If upgrade is not possible, enforce per‑IP rate limiting at the web server or firewall level, or add a lock around the registration guard to serialize requests.
Risk context
The CVE has a medium severity score (CVSS v3 3.7, v4 6.3) and a very low EPSS of 0.00223, indicating a low likelihood of exploitation in the wild. Nonetheless, the vulnerability can be abused by automated scripts to create many accounts, so timely patching is recommended.
Affected products
- LaraDashboard 1.4.0-1.4.7
Scores
- Severity
- medium
- CVSS v2
- 2.6
- CVSS v3
- 3.7
- CVSS v4
- 6.3
- EPSS
- 0.00223