PT-2026-104595 · Laradashboard · Laradashboard

·

CVE-2026-105129

·

Published

2026-10-03

·

Updated

2026-10-04

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105129

Affected Products

Laradashboard