Description
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
Published: 2026-09-07
Score: 8.6 High
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the MarketplaceModuleBrowser Livewire component in Lara Dashboard. The installModule action does not enforce the ModulePolicy authorization check, permitting any authenticated administrator who is not a superadmin to trigger installation of modules. Because the marketplace can supply arbitrary PHP code, successfully invoking this action leads to remote code execution on the host.

Affected Systems

Affected versions are all releases of the laradashboard:laradashboard package prior to 1.3.2, including the 1.3.1 build. The component resides in the Livewire file MarketplaceModuleBrowser.php and the missing check is linked to ModulePolicy.php. Upgrading to version 1.3.2 or later applies the necessary authorization guard.

Risk and Exploitability

With a CVSS score of 8.6 the flaw is classified as High severity. The EPSS score is not provided, and the vulnerability has not been cataloged as a known exploited vulnerability by CISA. An attacker must be an authenticated non-superadmin administrator, which is commonly possible in most setups; through the unsigned HTTP request channel, the attacker can download and activate any module, effectively gaining remote code execution. The absence of any network barrier or additional privileges markedly increases the risk.

Generated by OpenCVE AI on September 7, 2026 at 23:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest stable release (1.3.2 or newer) where the authorization check has been added.
  • If an upgrade is not immediately possible, restrict access to the Marketplace module by revoking install permissions for non-superadmin accounts or by disabling the Marketplace feature entirely.
  • Ensure that all HTTP requests to the marketplace are served over HTTPS and verify package signatures before installation; this reduces the chance of a malicious module being served.
  • Apply a manual patch by adding a proper authorization check in the installModule action referencing the ModulePolicy.

Generated by OpenCVE AI on September 7, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
Title Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action
First Time appeared Laradashboard
Laradashboard lara Dashboard
Weaknesses CWE-862
CPEs cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
Vendors & Products Laradashboard
Laradashboard lara Dashboard
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Laradashboard Lara Dashboard
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T15:03:37.121Z

Reserved: 2026-09-07T12:34:31.457Z

Link: CVE-2026-86438

cve-icon Vulnrichment

Updated: 2026-09-10T14:24:53.266Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T22:17:22.163

Modified: 2026-09-10T16:18:02.913

Link: CVE-2026-86438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T00:15:16Z

Weaknesses