CVE-2026-105129
LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
| CWE | CWE-863 |
| Vendor | laradashboard |
| Product | laradashboard |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for laradashboard laradashboard
Be the first to know when new medium vulnerabilities affecting laradashboard laradashboard are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
laradashboard / laradashboard
0 < 1.4.8
References
github.com: https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xgmw-7ppx-v7hq github.com: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/SettingController.php#L23-L50 github.com: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResource.php#L17-L26 github.com: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#L15-L34 github.com: https://github.com/laradashboard/laradashboard/pull/340 github.com: https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2dbe3 github.com: https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8 github.com: https://github.com/laradashboard/laradashboard vulncheck.com: https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api
Credits
EVIL0RD