Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation, without applying basename(), and without verifying that the resolved path remains inside storage/app/core-backups; the corresponding form requests only validate the value as a bounded string. An authenticated user holding only the delegated settings.edit permission (not Superadmin) can supply ../ traversal sequences to delete arbitrary files reachable on the host filesystem, including outside the application tree, or to restore a ZIP archive from an arbitrary on-disk location, writing arbitrary files into the application directories and achieving remote code execution. Note: the advisory states the vulnerable concatenation was introduced in the v0.9.7 release line. No patched version was available at the time of publication. | |
| Title | LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE | |
| First Time appeared |
Laradashboard
Laradashboard lara Dashboard |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Laradashboard
Laradashboard lara Dashboard |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T12:48:27.487Z
Reserved: 2026-09-14T11:33:51.886Z
Link: CVE-2026-90932
No data.
Status : Received
Published: 2026-09-14T13:19:31.523
Modified: 2026-09-14T13:19:31.523
Link: CVE-2026-90932
No data.
OpenCVE Enrichment
Updated: 2026-09-14T20:45:08Z