Skip to content
Threat Feed
high advisory

LaraDashboard Privilege Escalation Vulnerability

LaraDashboard versions prior to 1.4.8 contain an improper privilege management flaw that allows authenticated Admin users to escalate privileges to Superadmin, potentially leading to remote code execution.

CVE search metadata

CVE search record: CVE-2026-105126. Severity: high. CVSS: 7.2. KEV: no. Product: LaraDashboard (< 1.4.8). Brief: LaraDashboard Privilege Escalation Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-laradashboard-priv-esc/

LaraDashboard versions before 1.4.8 are susceptible to an improper privilege management vulnerability, identified as CVE-2026-105126. This vulnerability permits an authenticated user who already possesses 'role.edit' permissions to elevate their privileges to 'Superadmin'. By either renaming their current role to 'Superadmin' or modifying existing role permissions to include 'user.login_as', the attacker can assume the identity of other users. Once escalated, the attacker gains access to critical system functions, such as module installation and core configuration updates, which can be leveraged to achieve remote code execution. The vulnerability stems from insufficient server-side validation of role modification requests. Given the potential for full system compromise, upgrading to version 1.4.8 or later is critical.

Impact

Successful exploitation of this vulnerability allows an authenticated user to achieve full administrative control over the LaraDashboard instance. This leads to unauthorized account takeover, potential data exfiltration, and remote code execution by installing malicious modules, effectively compromising the integrity and confidentiality of the entire application environment.

Recommendation

Prioritized actions for the security team:

  • Upgrade all instances of LaraDashboard to version 1.4.8 or later to remediate CVE-2026-105126.
  • Audit existing role assignments and permission configurations to identify unauthorized 'Superadmin' roles created by standard 'Admin' accounts.
  • Review access logs for 'role.edit' or 'user.login_as' actions performed by non-Superadmin accounts to detect potential exploitation attempts.

Immediate actions

Upgrade LaraDashboard to 1.4.8 or later

IT Operations 24h

Mitigations

Upgrade to 1.4.8

immediate IT Operations

CVE-2026-105126