Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without… (CVE-2026-86436)
Lara Dashboard versions before 1.3.2 contain an authorization flaw in the post-builder image and video upload endpoints. This flaw allows authenticated users without proper content permissions to upload files. Malicious actors can exploit this by uploading polyglot files with attacker-controlled extensions to the public web root, potentially leading to remote code execution if the deployment permits execution of such files.
AI Analysis
Technical Summary
The vulnerability in Lara Dashboard prior to version 1.3.2 is an authorization bypass (CWE-862) affecting the post-builder image and video upload endpoints. Authenticated users lacking content upload permissions can still upload files. Attackers may upload polyglot files with chosen extensions to the public web root, which could lead to code execution if the server executes uploaded file types. The CVSS 3.1 base score is 5.4 (medium severity), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, unchanged scope, no confidentiality impact, limited integrity impact, and high availability impact.
Potential Impact
The vulnerability allows unauthorized authenticated users to upload files to the server, potentially leading to remote code execution if the server executes uploaded files. This can result in integrity and availability impacts to the affected system. There is no indication of confidentiality impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
A fix is available in Lara Dashboard version 1.3.2. Users should upgrade to version 1.3.2 or later to remediate this authorization bypass vulnerability. Since no vendor advisory content is provided, patch status is based on the version information given. There are no additional vendor-provided mitigation instructions.
Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without… (CVE-2026-86436)
Description
Lara Dashboard versions before 1.3.2 contain an authorization flaw in the post-builder image and video upload endpoints. This flaw allows authenticated users without proper content permissions to upload files. Malicious actors can exploit this by uploading polyglot files with attacker-controlled extensions to the public web root, potentially leading to remote code execution if the deployment permits execution of such files.
CVSS v3.1
Score 5.4medium
Affected software
pkg:github/laradashboard/laradashboardRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Lara Dashboard prior to version 1.3.2 is an authorization bypass (CWE-862) affecting the post-builder image and video upload endpoints. Authenticated users lacking content upload permissions can still upload files. Attackers may upload polyglot files with chosen extensions to the public web root, which could lead to code execution if the server executes uploaded file types. The CVSS 3.1 base score is 5.4 (medium severity), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, unchanged scope, no confidentiality impact, limited integrity impact, and high availability impact.
Potential Impact
The vulnerability allows unauthorized authenticated users to upload files to the server, potentially leading to remote code execution if the server executes uploaded files. This can result in integrity and availability impacts to the affected system. There is no indication of confidentiality impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
A fix is available in Lara Dashboard version 1.3.2. Users should upgrade to version 1.3.2 or later to remediate this authorization bypass vulnerability. Since no vendor advisory content is provided, patch status is based on the version information given. There are no additional vendor-provided mitigation instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v24q-8gmj-8457
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-86436"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a9f910facd9273b49ff2a8b
Added to database: 09/08/2026, 04:37:35 UTC
Last enriched: 09/08/2026, 05:38:39 UTC
Last updated: 09/08/2026, 05:38:39 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.