HIGH 7.1 NVD
CVE-2026-105129
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored s
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
References
- https://github.com/laradashboard/laradashboard
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/Settin
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResou
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#
- https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-10-04 via NVD.
vulnfeed aggregates 10603 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.