Vulnerability  ·  2026-10-05

LaraDashboard: incorrect authorization lets settings.view users read plaintext AI provider API keys

VulnerabilityMedium impactGlobalCVE-2026-105129
NVD published CVE-2026-105129 (CVSS 6.5) on 2026-10-04 via VulnCheck for an incorrect authorization flaw in LaraDashboard before 1.4.8 that lets settings.view users retrieve plaintext AI provider API keys, mail credentials, passwords and tokens through the settings API.
A dashboard that stores plaintext AI provider keys and exposes them to low-privilege readers leaks the credentials to call LLM APIs - the same key material used for billing and data access. Niche project, low blast radius, precise CVE worth keeping.
The settings API does not enforce the correct authorization policy (CWE-863): users holding only settings.view permission can read stored secrets including AI provider API keys in plaintext via the settings endpoints.
LaraDashboard (laradashboard/laradashboard) < 1.4.8 (fixed in 1.4.8)
Upgrade to LaraDashboard 1.4.8 or later and rotate any exposed AI provider keys. Advisory: https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api and GHSA-xgmw-7ppx-v7hq.
NVD CVE-2026-105129VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →