CVE Notify: post #287046 — TG.ME

🚨 CVE-2026-86436
Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type.

🎖@cveNotify
GitHub
GitHub - laradashboard/laradashboard: ⚡ Lara Dashboard - CMS by Laravel - All In One solution to start your Laravel Application…
⚡ Lara Dashboard - CMS by Laravel - All In One solution to start your Laravel Application from Basic to Enterprise. Manages Users, Roles, Permissions, Modules, Settings, Translations, Contents, Mon...