CRITICAL 9.8 CVE-2026-86184 Published 5 Sept 2026

Lara Dashboard Auth Bypass

Worried this affects one of your servers?

Lara Dashboard before 1.3.0 has a serious authentication bypass vulnerability.

Attackers can exploit the screenshot-login route to log in as any user by using their email address, even if they're not authenticated.

This allows unauthorized access to user administration, settings, database contents, and even arbitrary code execution through the module installer.

This issue only affects installations where APP_ENV is not set to 'production'.

Reference: CVE-2026-86184 on NVD

← Back to Security News