CVE-2026-105126: LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.loginas permissions to take over accounts and reach core upgrade and module installation functions for code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LaraDashboardto a version that resolves this vulnerability.Fixed in 1.4.8
Event History
Frequently Asked Questions
Which users can exploit this issue?
An authenticated Admin user who has the role.edit permission can exploit it. The attack does not require user interaction and can be performed remotely.
What access can an attacker gain after successful exploitation?
The attacker can escalate to Superadmin by renaming their role to Superadmin, or grant user.login_as permissions to take over other accounts. Superadmin access can reach core upgrade and module installation functions, creating a path to code execution.
Are deployments running version 1.4.8 affected?
The issue affects LaraDashboard versions before 1.4.8. Version 1.4.8 is not identified as affected by the provided advisory information.
What should be reviewed while remediation is pending?
Review which Admin users and roles have role.edit, and restrict that permission to only fully trusted administrators. Investigate role names and permissions for unexpected Superadmin assignments or user.login_as grants.