← Back
Web Application
CVE-2026-86438 high CVSS 7.2

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-ac...

Summary

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code...

AI summary openai / gpt-4o

Lara Dashboardのバージョン1.3.2以前では、非Superadminの管理者がモジュールをインストールできるという問題がありました。これにより、攻撃者は署名されていないHTTPリクエストを介して悪意のあるPHPモジュールをダウンロードし、自動的にアクティブ化することが可能です。この脆弱性はリモートコード実行を許し、高いリスクがあります。
❓ What is the problem
非Superadminの管理者がモジュールをインストールできる認可不足の問題。
📍 Affected scope
Lara Dashboardのバージョン1.3.2以前。
🔥 Severity
この問題により、攻撃者がリモートで任意のコードを実行できるため、高リスクである。
🔧 How to fix
バージョン1.3.2にアップデートすることで修正される。
🛡️ Workaround
Superadmin以外の管理者からのモジュールインストールを一時的に制限する。
🔍 Detection
システムログとインストールされたモジュールの確認を行い、不正なインストールがないかチェックする。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →