{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/laradashboard--1.4.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:laradashboard:laradashboard:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-105126"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LaraDashboard (\u003c 1.4.8)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LaraDashboard"],"content_html":"\u003cp\u003eLaraDashboard versions before 1.4.8 are susceptible to an improper privilege management vulnerability, identified as CVE-2026-105126. This vulnerability permits an authenticated user who already possesses 'role.edit' permissions to elevate their privileges to 'Superadmin'. By either renaming their current role to 'Superadmin' or modifying existing role permissions to include 'user.login_as', the attacker can assume the identity of other users. Once escalated, the attacker gains access to critical system functions, such as module installation and core configuration updates, which can be leveraged to achieve remote code execution. The vulnerability stems from insufficient server-side validation of role modification requests. Given the potential for full system compromise, upgrading to version 1.4.8 or later is critical.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated user to achieve full administrative control over the LaraDashboard instance. This leads to unauthorized account takeover, potential data exfiltration, and remote code execution by installing malicious modules, effectively compromising the integrity and confidentiality of the entire application environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for the security team:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of LaraDashboard to version 1.4.8 or later to remediate CVE-2026-105126.\u003c/li\u003e\n\u003cli\u003eAudit existing role assignments and permission configurations to identify unauthorized 'Superadmin' roles created by standard 'Admin' accounts.\u003c/li\u003e\n\u003cli\u003eReview access logs for 'role.edit' or 'user.login_as' actions performed by non-Superadmin accounts to detect potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-04T00:59:10Z","date_published":"2026-10-04T00:59:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-laradashboard-priv-esc/","summary":"LaraDashboard versions prior to 1.4.8 contain an improper privilege management flaw that allows authenticated Admin users to escalate privileges to Superadmin, potentially leading to remote code execution.","title":"LaraDashboard Privilege Escalation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-laradashboard-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - LaraDashboard (\u003c 1.4.8)","version":"https://jsonfeed.org/version/1.1"}