CVE-2026-105129
Deferred Deferred - Pending Action

Incorrect Authorization in LaraDashboard Allows Unauthorized Access to Stored Secrets

Vulnerability report for CVE-2026-105129, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
laradashboard laradashboard to 1.4.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

LaraDashboard before version 1.4.8 has an incorrect authorization vulnerability where authenticated users with only settings.view permission can read stored secrets through the settings API. Attackers can query endpoints like GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords, and tokens.

Detection Guidance

Check if your LaraDashboard version is below 1.4.8. Use commands like curl to query GET /api/settings or /api/settings/{option_name} endpoints. If plaintext secrets are returned, the system is vulnerable.

Impact Analysis

This vulnerability allows attackers to access sensitive credentials like API keys, passwords, and tokens, potentially leading to unauthorized access to systems, data breaches, or further attacks such as phishing or quota exhaustion for API services.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR (data protection) and HIPAA (health information security) due to unauthorized access to sensitive data like passwords and API keys, potentially resulting in data breaches and regulatory penalties.

Mitigation Strategies

Upgrade LaraDashboard to version 1.4.8 or later. Restrict API access to trusted users. Review and re-save plaintext secrets to encrypt them. Monitor logs for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105129. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart