---
id: CVE-2026-105129
title: >-
  LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability
  that allows authenticated users with only settings.view permission to read
  stored secrets through the settings API
summary: >-
  LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability
  that allows authenticated users with only settings.view permission to read
  stored secrets through the settings API. Attackers can query GET /api/settings
  or /ap…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: laradashboard
product: laradashboard
affected:
  - laradashboard < 1.4.8
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T00:16:36.843'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105129'
references:
  - url: 'https://github.com/laradashboard/laradashboard'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/SettingController.php#L23-L50
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResource.php#L17-L26
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#L15-L34
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2dbe3
    label: disclosure@vulncheck.com
  - url: 'https://github.com/laradashboard/laradashboard/pull/340'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xgmw-7ppx-v7hq
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T00:50:56.109Z'
epss: 0.00306
epssPercentile: 0.21279
---

## Overview

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
