PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86438 laradashboard CVE debrief

CVE-2026-86438 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T22:17:22.163Z and has not been modified since then. This vulnerability affects Lara Dashboard installations prior to version 1.3.2, allowing non-Superadmin administrators to install arbitrary PHP modules via the MarketplaceModuleBrowser installModule Livewire action, potentially leading to remote code execution. Defenders should assess exposure, review module installation policies, and prioritize upgrading to version 1.3.2 or later.

Vendor
laradashboard
Product
Unknown
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

Defenders responsible for Lara Dashboard installations should assess exposure and prioritize upgrading to version 1.3.2 or later. This includes reviewing module installation policies, verifying current version, and ensuring that Livewire actions are properly secured. Security teams and vulnerability management teams should also review the vulnerability and implement compensating controls if necessary.

Why it matters

CVE-2026-86438 is significant for defenders of Lara Dashboard installations, as it allows non-Superadmin administrators to install arbitrary PHP modules, potentially leading to remote code execution. Defenders should verify exposure, review module installation policies, and prioritize upgrading to version 1.3.2 or later.

  • Potential remote code execution via unauthorized module installation
  • Exposure of Lara Dashboard installations to non-Superadmin administrators
  • Need for verification of current version and module installation policies

Technical summary

Lara Dashboard before version 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. This could potentially lead to remote code execution via arbitrary PHP module downloads and auto-activation. The vulnerability exists due to insufficient authorization checks, enabling attackers to exploit this weakness by downloading and activating malicious PHP modules. Defenders should prioritize verifying exposure of Lara Dashboard installations and upgrading to version 1.3.2 or later.

Defensive priority

Defenders should prioritize verifying exposure of Lara Dashboard installations and upgrading to version 1.3.2 or later.

Recommended defensive actions

  • Verify exposure of Lara Dashboard installations
  • Upgrade to version 1.3.2 or later
  • Review module installation policies and Livewire actions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from the CVE record and source references indicates that Lara Dashboard before version 1.3.2 is vulnerable to unauthorized module installation, potentially leading to remote code execution. The vulnerability is due to a failure in authorizing the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests. Defenders should verify exposure of Lara Dashboard installations and review current to

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86438 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86438

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86438 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86438

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.