Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution. | |
| Title | Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action | |
| First Time appeared |
Laradashboard
Laradashboard lara Dashboard |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Laradashboard
Laradashboard lara Dashboard |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-07T22:01:49.499Z
Reserved: 2026-09-07T12:34:31.457Z
Link: CVE-2026-86438
No data.
Status : Received
Published: 2026-09-07T22:17:22.163
Modified: 2026-09-07T22:17:22.163
Link: CVE-2026-86438
No data.
OpenCVE Enrichment
No data.
Weaknesses