CVE-2026-86438
Received Received - Intake

Lara Dashboard Admin Module Installation RCE Vulnerability

Vulnerability report for CVE-2026-86438, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: VulnCheck

Description

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lara_dashboard lara_dashboard to 1.3.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Lara Dashboard before version 1.3.2 has an authorization flaw in the MarketplaceModuleBrowser installModule Livewire action. Non-Superadmin administrators can exploit this to install arbitrary PHP modules from the marketplace via unsigned HTTP requests, leading to remote code execution.

Detection Guidance

Check Lara Dashboard versions before 1.3.2 for unauthorized module installations. Inspect network traffic for unsigned HTTP requests to marketplace domains and look for PHP module downloads or auto-activations by non-Superadmin users.

Impact Analysis

If you are an administrator using Lara Dashboard before 1.3.2, attackers could gain control of your system by installing malicious PHP modules. This could allow them to execute arbitrary code, steal data, or disrupt services.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's integrity and confidentiality requirements or HIPAA's security rules. Organizations may face fines or legal consequences for failing to protect sensitive data.

Mitigation Strategies

Upgrade Lara Dashboard to version 1.3.2 or later. Restrict module installation permissions to Superadmin only. Disable unsigned HTTP requests for marketplace interactions and monitor for unauthorized PHP module activations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86438. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart