OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-105126

HIGH · CVSS 7.2 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-04 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

LaraDashboard versions prior to 1.4.8 are vulnerable due to improper privilege management, enabling authenticated Admin users to escalate their privileges to Superadmin by editing or renaming roles. This flaw allows attackers with role.edit permissions to assume Superadmin status or gain access to user accounts, potentially leading to unauthorized code execution through core upgrades and module installations. Organizations using LaraDashboard should prioritize patching this vulnerability to mitigate the risk of privilege escalation and account takeover.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105126
Severity
HIGH
CVSS
7.2
EPSS
0.49%

Original NVD Description

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.