PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105128 laradashboard CVE debrief

CVE-2026-105128 is a MEDIUM-severity open redirect vulnerability in LaraDashboard before version 1.4.8. The vulnerability allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions, causing them to navigate to attacker-controlled phishing sites after saving a template.

Vendor
laradashboard
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for LaraDashboard instances, particularly those exposed to untrusted networks, should assess their exposure and prioritize upgrading to version 1.4.8 or later. They should also educate users on safely handling links in email templates.

Why it matters

CVE-2026-105128 is a MEDIUM-severity open redirect vulnerability in LaraDashboard before version 1.4.8. Defenders should prioritize verifying exposure and upgrading to mitigate potential phishing attacks.

  • Phishing site navigation after saving email templates
  • Potential for attackers to redirect users to malicious sites
  • Need for verification of LaraDashboard version and exposure
  • Priority for upgrading to version 1.4.8 or later

Technical summary

The vulnerability exists in the EmailTemplateController builder and builderEdit due to an unvalidated redirect_url parameter. This allows attackers to craft links that, when accessed by logged-in users with email template permissions, redirect them to attacker-controlled phishing sites after saving a template. Defenders should prioritize verifying exposure of LaraDashboard instances to untrusted networks and upgrading to version 1.4.8 or later. They should also monitor for suspicious redirect URLs and educate users on safely handling links in email templates. The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification.

Defensive priority

Defenders should prioritize verifying exposure of LaraDashboard instances to untrusted networks and upgrading to version 1.4.8 or later. They should also monitor for suspicious redirect URLs and educate users on safely handling links in email templates.

Recommended defensive actions

  • Verify LaraDashboard version and upgrade to 1.4.8 or later if necessary
  • Monitor for suspicious redirect URLs in email templates
  • Educate users on safely handling links in email templates
  • Restrict access to EmailTemplateController builder and builderEdit
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification. The vendor has released a patched version (1.4.8) and provided source code details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105128 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105128

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105128 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105128

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.