Sceawere
Vulnerability Detail
CVE-2026-105126UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LaraDashboard Improper Privilege Management
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- laradashboard
- Product
- laradashboard
- Attack Type
- Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-04T00:16:36.217Z",
"pubdate": "2026-10-04T00:16:36.217Z",
"executiveSummary": "LaraDashboard versions prior to 1.4.8 are susceptible to a critical improper privilege management vulnerability.\nThe flaw stems from insufficient server-side validation during role modification processes.\nAn authenticated user possessing 'role.edit' permissions can maliciously elevate their privileges to 'Superadmin'.\nBy manipulating role names or assigning elevated permissions such as 'user.login_as', an attacker can assume administrative control over the application.\nThis escalation grants unauthorized access to sensitive administrative functions, including core system upgrades, module installations, and arbitrary code execution vectors.\nThe vulnerability represents a significant security risk, effectively bypassing the intended Role-Based Access Control (RBAC) model.\nSuccessful exploitation requires an authenticated session with low-level administrative permissions, but results in a complete system compromise by enabling full administrative escalation.",
"technicalDetails": "The vulnerability resides in the role management module of LaraDashboard, specifically within the logic responsible for editing or renaming existing system roles. The root cause is a failure to implement proper authorization checks on user-supplied input when defining or modifying role attributes, coupled with a lack of server-side sanitization regarding privileged role designations.\nThe attack flow initiates when an authenticated user with the 'role.edit' capability invokes the role update interface. Because the application logic fails to restrict specific reserved keywords or critical permission sets (such as 'Superadmin' or 'user.login_as') during the update request, an attacker can modify their assigned role properties to include these elevated attributes.\nStep-by-step exploitation: 1. The attacker authenticates into the dashboard using credentials associated with an account having 'role.edit' permissions. 2. The attacker navigates to the role management interface and initiates a request to rename their own role or modify the permission mapping assigned to their role. 3. By intercepting the request, the attacker alters the POST parameters to map their role to 'Superadmin' or injects elevated administrative permissions directly into the user-to-role relation schema. 4. Upon processing the request, the application backend updates the database with the malicious privileges without verifying the legitimacy of the request against the current user's session authority. 5. Once the role is elevated, the attacker gains access to 'user.login_as' functionality, which allows them to masquerade as other users, including existing Superadmins, or directly access core upgrade and module management interfaces.\nThe exploitation allows an attacker to achieve Remote Code Execution (RCE) by leveraging the now-accessible module installation functions to upload or deploy malicious code into the server environment. This bypasses all intended RBAC restrictions and creates a persistent backdoor, as the attacker can manipulate system configurations or further modify administrative accounts to maintain long-term access. The vulnerability affects all versions of LaraDashboard prior to 1.4.8 and is accessible over the network for any user with the ability to modify roles within the dashboard."
}