CVE-2026-105129
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 04, 2026
Vendor
unknown
Description
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
References
- https://github.com/laradashboard/laradashboard
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/SettingController.php#L23-L50
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResource.php#L17-L26
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#L15-L34
- https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2dbe3