CVE-2026-90932 | LaraDashboard up to 1.2.2 Core Upgrade Backup storage/app/core-backups deleteBackup backup_file path traversal
A vulnerability labeled as critical has been found in LaraDashboard up to 1.2.2. This affects the function BackupService::deleteBackup of the file storage/app/core-backups of the component Core Upgrade Backup Handler. Such manipulation of the argument backup_file leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-90932. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More