CVE-2026-90933: laradashboard through 1.2.2 Missing Authorization via License API

Published Sep 14, 2026
·
Updated

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store, and POST /api/admin/licenses/remove endpoints to disclose confidential license keys, inject attacker-controlled values, or delete stored licenses entirely.

Affected Software

1 affected component
laradashboard<=1.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade laradashboard Local License API to a version that resolves this vulnerability.

    Fixed in 1.2.2Patch Missing Authorization via License API

Event History

Sep 14, 2026
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit the affected license endpoints?

Any authenticated user, including a low-privileged account, can exploit the missing authorization controls. No user interaction is required.

2

Which operations can an unauthorized authenticated user perform?

An attacker can call GET /api/admin/licenses/show to read license keys, POST /api/admin/licenses/store to overwrite or inject license values, and POST /api/admin/licenses/remove to delete stored licenses.

3

What information and functionality are at risk?

Stored premium module license keys can be disclosed, replaced with attacker-controlled values, or removed entirely. The issue affects the Local License API endpoints in laradashboard through version 1.2.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203