Product
high
advisory
Arbitrary File Upload and RCE in Lara Dashboard
1 rule 2 TTPs 1 CVELara Dashboard versions prior to 1.3.2 are vulnerable to arbitrary file upload via the core-upgrades endpoint, allowing unauthorized administrators to achieve remote code execution.
Lara Dashboard
web-application-vulnerability
rce
file-upload
1r
2t
1c
critical
advisory
Authentication Bypass in Lara Dashboard
2 rules 3 TTPs 1 CVELara Dashboard versions prior to 1.3.0 are vulnerable to an authentication bypass in the screenshot-login route that permits unauthenticated access to any user account when APP_ENV is not set to production.
Lara Dashboard +2
vulnerability
authorization-bypass
remote-code-execution
web-application
ssrf
cve-2026-87821
2r
3t
1c
updated