Arbitrary File Upload Vulnerability in Lara Dashboard by Laradashboard
CVE-2026-86437
8.6HIGH
What is CVE-2026-86437?
An authorization flaw in Lara Dashboard prior to version 1.3.2 allows administrators, lacking super admin privileges, to upload and execute arbitrary zip archives via the /admin/settings/core-upgrades/upload endpoint. This vulnerability enables attackers to inject harmful files into the application's source code. These files, when processed by the server, can execute malicious commands with the same permissions as the web server, potentially exposing sensitive environment information and database credentials.
Affected Version(s)
laradashboard 0 < 1.3.2
laradashboard 1.3.2
