LaraDashboard Privilege Escalation Vulnerability
LaraDashboard versions prior to 1.4.8 contain an improper privilege management flaw that allows authenticated Admin users to escalate privileges to Superadmin, potentially leading to remote code execution.
CVE search metadata
CVE search record: CVE-2026-105126. Severity: high. CVSS: 7.2. KEV: no. Product: LaraDashboard (< 1.4.8). Brief: LaraDashboard Privilege Escalation Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-laradashboard-priv-esc/
LaraDashboard versions before 1.4.8 are susceptible to an improper privilege management vulnerability, identified as CVE-2026-105126. This vulnerability permits an authenticated user who already possesses 'role.edit' permissions to elevate their privileges to 'Superadmin'. By either renaming their current role to 'Superadmin' or modifying existing role permissions to include 'user.login_as', the attacker can assume the identity of other users. Once escalated, the attacker gains access to critical system functions, such as module installation and core configuration updates, which can be leveraged to achieve remote code execution. The vulnerability stems from insufficient server-side validation of role modification requests. Given the potential for full system compromise, upgrading to version 1.4.8 or later is critical.
Impact
Successful exploitation of this vulnerability allows an authenticated user to achieve full administrative control over the LaraDashboard instance. This leads to unauthorized account takeover, potential data exfiltration, and remote code execution by installing malicious modules, effectively compromising the integrity and confidentiality of the entire application environment.
Recommendation
Prioritized actions for the security team:
- Upgrade all instances of LaraDashboard to version 1.4.8 or later to remediate CVE-2026-105126.
- Audit existing role assignments and permission configurations to identify unauthorized 'Superadmin' roles created by standard 'Admin' accounts.
- Review access logs for 'role.edit' or 'user.login_as' actions performed by non-Superadmin accounts to detect potential exploitation attempts.
Immediate actions
Upgrade LaraDashboard to 1.4.8 or later
Mitigations
Upgrade to 1.4.8
CVE-2026-105126