MEDIUM 5.3 NVD
CVE-2026-86436
Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content perm
Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type.
References
- https://github.com/laradashboard/laradashboard
- https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Controllers/Backend/Po
- https://github.com/laradashboard/laradashboard/blob/v1.3.1/routes/web.php#L243-L244
- https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8
- https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-07 via NVD.
vulnfeed aggregates 10421 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.