Unauthorized File Upload Vulnerability in Lara Dashboard by Lara Technologies
CVE-2026-86436

5.3MEDIUM

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-86436?

The Lara Dashboard, up to version 1.3.1, exhibits a vulnerability that permits authenticated users without the necessary content permissions to upload files via the post-builder image and video upload endpoints. This flaw enables attackers to exploit the system, allowing them to upload malicious polyglot files with custom extensions directly to the public web root. If the deployment is configured to execute uploaded file types, this can lead to severe security breaches, including unauthorized code execution.

Affected Version(s)

laradashboard 0 < 1.3.2

laradashboard 1.3.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EVIL0RD
.