Junglewise Threat Intelligence

CVE-2026-90932: LaraDashboard path traversal in backup handling

CVE-2026-90932 · Severity: high · CVSS 7.2 · Published 2026-09-14

Technologies: LaraDashboard. Vendors: LaraDashboard.

Executive brief

LaraDashboard is a Laravel-based admin dashboard tool used for managing application settings and backup archives. A path traversal vulnerability in its core-upgrade backup feature allows non-administrator users with basic settings management permissions to delete arbitrary files from the server or restore malicious archives that overwrite application code, leading to complete system compromise and remote code execution.

Technical details

The vulnerability is a path traversal flaw (CWE-73) in CoreUpgradeController and BackupService where user-supplied backup_file parameters are concatenated directly onto the backup directory path without normalization, basename() filtering, or verification that the resolved path stays within the intended backup directory. An authenticated user holding only the delegated settings.edit permission (not Superadmin) can supply ../ sequences to traverse the filesystem. The attack has two impacts: (1) arbitrary file deletion anywhere on the filesystem reachable through directory traversal, potentially deleting .env, storage, or the database to cause denial of service; (2) arbitrary file write via restore functionality, which accepts attacker-controlled ZIP paths and extracts them into application directories (app, routes, config, bootstrap, vendor), allowing code injection and remote code execution. The form validation only checks for a bounded string (max 255 chars), never stripping traversal sequences. The vulnerable code has existed since v0.9.7. No patched version was available at publication.

Affected products

  • LaraDashboard LaraDashboard 0.9.2 through 1.2.2

Timeline

  • 2026-09-14: disclosed: Advisory published
  • 2026-08-30: other: GitHub Security Advisory GHSA-g48h-h5pc-396j published

References

Related threats