CVE-2026-105129: Laradashboard

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

Affected products

Published 2026-10-04. Last modified 2026-10-06.