8.6
CVE-2026-105126
- EPSS 0.49%
- Veröffentlicht 03.10.2026 23:39:59
- Zuletzt bearbeitet 05.10.2026 21:16:33
- Erkennungen
LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerlaradashboard
≫
Produkt
laradashboard
Default Statusunaffected
Version
0
Version <
1.4.8
Status
affected
Version
1.4.8
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.401 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.6 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://github.com/laradashboard/laradashboard
https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8
https://github.com/laradashboard/laradashboard/security/advisories/GHSA-555v-6rfr-r969
https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L144
https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L180
https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/RolePolicy.php#L39-L50
https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/CoreUpgrade/UploadRequest.php#L23
https://github.com/laradashboard/laradashboard/pull/344
https://github.com/laradashboard/laradashboard/commit/286f150e4d0c924ec1ce7eb256b2326e871e9517
https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-privilege-escalation-via-superadmin-role-tampering