CVE-2026-105129

Source
https://cve.org/CVERecord?id=CVE-2026-105129
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105129.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105129
Aliases
  • GHSA-xgmw-7ppx-v7hq
Published
2026-10-03T23:40:01Z
Modified
2026-10-07T02:31:06Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API
Details

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105129.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "1.4.8"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "1.4.8"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "1.4.8"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/laradashboard/laradashboard

Affected ranges

Type
GIT
Repo
https://github.com/laradashboard/laradashboard
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
Day1
Day10
Day2
Day3
Day4
Day5
Day6
Day7
Day8
Day9
Laravel11.*
Laravel11.x
Laravel12.*
Laravel12.x-module-logs
Laravel12.x-tailadmin
Laravel7.*
Laravel7.x
Laravel9.*
Laravel9.x
v0.*
v0.9.0
v0.9.10
v0.9.11
v0.9.12
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.9
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.1.0
v1.1.5
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.4.2
v1.4.5
v1.5.0
v1.5.1
v1.6.0
v11.*
v11.x-main
v2.*
v2.0.1
v2.1.0
v2.2.0
v2.3.0
v2.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105129.json"