laradashboard vulnerability

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.

Published 7 Sep 2026Updated 7 Sep 20267 sources
CVSS 8.6

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.