What happened
NVD published CVE-2026-105129 (CVSS 6.5) on 2026-10-04 via VulnCheck for an incorrect authorization flaw in LaraDashboard before 1.4.8 that lets settings.view users retrieve plaintext AI provider API keys, mail credentials, passwords and tokens through the settings API.
Why it matters
A dashboard that stores plaintext AI provider keys and exposes them to low-privilege readers leaks the credentials to call LLM APIs - the same key material used for billing and data access. Niche project, low blast radius, precise CVE worth keeping.
Attack vector
The settings API does not enforce the correct authorization policy (CWE-863): users holding only settings.view permission can read stored secrets including AI provider API keys in plaintext via the settings endpoints.
Affected systems
LaraDashboard (laradashboard/laradashboard) < 1.4.8 (fixed in 1.4.8)
Mitigation
Upgrade to LaraDashboard 1.4.8 or later and rotate any exposed AI provider keys. Advisory: https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api and GHSA-xgmw-7ppx-v7hq.