CVE-2026-86438

Summary

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.

Affected Software

VendorProductVersion RangeStatus
laradashboardlaradashboard0 < 1.3.2affected
laradashboardlaradashboard1.3.2unaffected

Weaknesses

  • CWE-862: Missing Authorization

References