LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 04 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution. | |
| Title | LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering | |
| First Time appeared |
Laradashboard
Laradashboard lara Dashboard |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Laradashboard
Laradashboard lara Dashboard |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-03T23:39:59.775Z
Reserved: 2026-10-03T12:05:26.755Z
Link: CVE-2026-105126
No data.
Status : Deferred
Published: 2026-10-04T00:16:36.217
Modified: 2026-10-04T00:16:36.340
Link: CVE-2026-105126
No data.
OpenCVE Enrichment
Updated: 2026-10-04T02:00:05Z
Weaknesses