PatchSiren cyber security CVE debrief
CVE-2026-105126 laradashboard CVE debrief
CVE-2026-105126 is a high-severity vulnerability in LaraDashboard before version 1.4.8, allowing authenticated Admin users to escalate privileges to Superadmin by editing or renaming roles. This could enable attackers with role.edit permissions to rename their role to Superadmin or grant user.login_as permissions, potentially leading to code execution through core upgrade and module installation functions.
- Vendor
- laradashboard
- Product
- Unknown
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for LaraDashboard installations, security teams, and administrators of the affected systems should assess exposure and prioritize remediation. This includes reviewing system configurations, verifying role permissions, and ensuring that all users with role.edit permissions are properly monitored. Additionally, defenders should consider implementing compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
CVE-2026-105126 is a high-severity vulnerability in LaraDashboard that allows authenticated Admin users to escalate privileges to Superadmin, potentially leading to code execution. Defenders should prioritize verification, upgrading, and monitoring to mitigate this vulnerability.
- Potential privilege escalation to Superadmin
- Possible code execution through core upgrade and module installation functions
- Increased risk of account takeover through user.login_as permissions
- Need for verification and upgrade to version 1.4.8 or later
Technical summary
The vulnerability exists in LaraDashboard before version 1.4.8, where authenticated Admin users can escalate privileges to Superadmin by editing or renaming roles. This is due to improper privilege management, allowing attackers with role.edit permissions to rename their role to Superadmin or grant user.login_as permissions. This could enable attackers to potentially leading to code execution through core upgrade and module installation functions. The CVE record and source references indicate a privilege escalation vulnerability in LaraDashboard. Official references include the CVE Program record, NVD vulnerability detail, and source references from GitHub repositories.
Defensive priority
Defenders should prioritize verifying and upgrading to version 1.4.8 or later, restricting role editing and renaming capabilities, and monitoring for suspicious role changes or login activity.
Recommended defensive actions
- Verify and upgrade to LaraDashboard version 1.4.8 or later
- Restrict role editing and renaming capabilities to authorized personnel
- Monitor for suspicious role changes or login activity
- Implement additional access controls and logging for core upgrade and module installation functions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source references indicate a privilege escalation vulnerability in LaraDashboard. Official references include the CVE Program record, NVD vulnerability detail, and source references from GitHub repositories.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105126 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105126
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105126 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105126
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/laradashboard/laradashboard
-
Source reference
Unverified legacy reference
URL: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php
-
Source reference
Unverified legacy reference
URL: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/CoreUpgrade/UploadRequest.php
-
Source reference
Unverified legacy reference
URL: https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/RolePolicy.php
-
Source reference
Unverified legacy reference
URL: https://github.com/laradashboard/laradashboard/commit/286f150e4d0c924ec1ce7eb256b2326e871e9517
-
Source reference
Unverified legacy reference
URL: https://github.com/laradashboard/laradashboard/pull/344
-
Source reference
Unverified legacy reference
URL: https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8
-
Source reference
Unverified legacy reference
URL: https://github.com/laradashboard/laradashboard/security/advisories/GHSA-555v-6rfr-r969
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.