๐Ÿ” CVE Alert

CVE-2026-105129

MEDIUM 6.5

LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

CWE CWE-863
Vendor laradashboard
Product laradashboard
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for laradashboard laradashboard

Be the first to know when new medium vulnerabilities affecting laradashboard laradashboard are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

laradashboard / laradashboard
0 < 1.4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xgmw-7ppx-v7hq github.com: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/SettingController.php#L23-L50 github.com: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResource.php#L17-L26 github.com: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#L15-L34 github.com: https://github.com/laradashboard/laradashboard/pull/340 github.com: https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2dbe3 github.com: https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8 github.com: https://github.com/laradashboard/laradashboard vulncheck.com: https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api

Credits

EVIL0RD