CVE-2026-86438 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T22:17:22.163Z and has not been modified since then. This vulnerability affects Lara Dashboard installations prior to version 1.3.2, allowing non-Superadmin administrators to install arbitrary PHP modules via the MarketplaceModuleBrowser installModule Livewire action, potentially leading to remote code ex [truncated]
CVE-2026-86437 debrief: Lara Dashboard before 1.3.2 has a vulnerability in the POST /admin/settings/core-upgrades/upload endpoint, allowing non-Superadmin administrators with settings.edit permission to upload and extract arbitrary zip archives over the live application source code. This could lead to potential code execution and unauthorized access. Defenders should assess exposure and apply remediation, [truncated]
CVE-2026-86436 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T22:17:21.833Z and has not been modified since then. This medium-severity vulnerability in Lara Dashboard allows unauthorized file uploads, potentially leading to code execution. Defenders should assess exposure, especially in publicly accessible deployments, and prioritize remediation. The vulnerability [truncated]