rootpwn

medium · CVSS v3 3.7 · CVSS v4 6.3 · EPSS 0.00223

CVE-2026-105130

LaraDashboard versions 1.4.0 through 1.4.7 contain a race condition in the registration flow that lets attackers create accounts from a sing

Overview

LaraDashboard versions 1.4.0 through 1.4.7 contain a race condition in the registration flow that lets attackers create accounts from a single IP without hitting the daily limit. This bypasses anti‑automation controls and can lead to mass account creation. The flaw is triggered by concurrent registration requests.

Description

LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.

Impact

Confidentiality: attackers can create arbitrary user accounts, potentially gaining access to privileged resources. Integrity: the system's anti‑automation controls are subverted, allowing automated account creation. Availability: large numbers of accounts may strain resources. Defenders: administrators of LaraDashboard installations must patch or mitigate.

Remediation

Apply the official patch to upgrade to version 1.4.8 or later. If upgrade is not possible, enforce per‑IP rate limiting at the web server or firewall level, or add a lock around the registration guard to serialize requests.

Risk context

The CVE has a medium severity score (CVSS v3 3.7, v4 6.3) and a very low EPSS of 0.00223, indicating a low likelihood of exploitation in the wild. Nonetheless, the vulnerability can be abused by automated scripts to create many accounts, so timely patching is recommended.

Affected products

  • LaraDashboard 1.4.0-1.4.7

Scores

Severity
medium
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
6.3
EPSS
0.00223

race condition registration rate limiting account creation LaraDashboard medium severity EPSS low

← All CVEs