Sceawere
Vulnerability Detail
CVE-2026-105129UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LaraDashboard Incorrect Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- laradashboard
- Product
- laradashboard
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-04T00:16:36.730Z",
"pubdate": "2026-10-04T00:16:36.730Z",
"executiveSummary": "An incorrect authorization vulnerability has been identified in LaraDashboard versions prior to 1.4.8. This vulnerability allows authenticated users with low-privilege roles to bypass intended access controls and retrieve sensitive system configuration data. Specifically, any user account provisioned with only the 'settings.view' permission can abuse the application's settings API to access restricted configuration variables.\nThe risk implications of this flaw are critical, as it exposes highly sensitive administrative secrets in plaintext, including artificial intelligence provider API keys, SMTP mail credentials, system passwords, and third-party authentication tokens. An attacker exploiting this vulnerability can elevate their capabilities from a low-privileged dashboard viewer to a fully compromised position, enabling lateral movement across external services and internal databases linked to the exposed credentials.\nExploitation requires valid authentication credentials with minimal view-level permissions on the target LaraDashboard instance. Because the vulnerability lies within the standard application programming interface (API), it can be exploited remotely over the network without requiring sophisticated user interaction or complex exploitation techniques, making it a high-priority security concern.",
"technicalDetails": "The vulnerability lies within the access control mechanisms of the LaraDashboard API component, specifically affecting all versions of the software prior to 1.4.8. The root cause is an incorrect authorization implementation where the application fails to distinguish between permission to view metadata about settings versus permission to access the actual, sensitive values of those settings. Although a user may only be granted the 'settings.view' privilege—intended to permit basic read-only access to benign application configuration parameters—the backend API endpoints do not apply sufficient filtering or masking rules to the returned JSON payloads. Consequently, the application exposes raw, plaintext secrets stored within the database directly to any querying client that possesses this low-level authorization token.\nThe exploitation vector is straightforward and involves interacting directly with the LaraDashboard REST API. An attacker authenticated with the 'settings.view' permission can initiate unauthorized read requests to retrieve the sensitive configuration state. The vulnerability can be exploited via two primary API pathways: a bulk retrieval request targeting 'GET /api/settings' or a targeted resource request targeting 'GET /api/settings/{option_name}', where '{option_name}' represents a specific configuration key (e.g., mail server passwords or API tokens). When these endpoints are queried, the backend controller processes the request, validates that the user possesses the 'settings.view' permission, and queries the database for the corresponding settings. However, due to the lack of access control checks on specific fields or data masking policies, the API responds with the complete, unredacted records.\nThe payload returned by the server contains high-value administrative secrets in plaintext. Specifically, the JSON response bodies for these API endpoints expose critical assets such as artificial intelligence provider API keys, mail credentials (including SMTP host details and credentials), passwords, and tokens. In a post-exploitation scenario, the implications are extensive. With the recovered SMTP credentials, an attacker can hijack the mail-sending infrastructure to perform phishing campaigns or intercept password reset tokens. Access to AI provider API keys could lead to service abuse, financial theft through resource consumption, or data exfiltration. Furthermore, exposed administrative passwords and integration tokens allow the attacker to compromise associated third-party services and potentially pivot deeper into the host network or connected cloud infrastructure."
}