← Back
CVE-2026-86436 medium CVSS 5.4

Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can u...

Summary

Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the...

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →