CVE-2026-54175

Source
https://cve.org/CVERecord?id=CVE-2026-54175
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54175.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54175
Aliases
Published
2026-09-14T17:46:41Z
Modified
2026-09-16T03:46:31Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
Summary
backpack/crud: Unverified password change in MyAccountController via mass assignment
Details

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm in src/app/Http/Controllers/MyAccountController.php at POST /admin/edit-account-info passes request data from $request->except(['_token']) to the user model instead of restricting updates to fields accepted by AccountInfoRequest::validationData(). An attacker with an authenticated Backpack session can therefore mass-assign password, the authentication column, or other deployment-specific fillable attributes. With the default Laravel 11 user model, a submitted plaintext password is automatically hashed and persisted, converting temporary session access into persistent account takeover without the old_password check enforced by the separate password-change route. Changing the authentication email can also enable later password-reset takeover, while additional fillable security attributes can permit deployment-specific privilege escalation or security-control changes. This issue is fixed in versions 6.8.11 and 7.0.34.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-620"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54175.json"
}
References

Affected packages

Git / github.com/laravel-backpack/crud

Affected ranges

Type
GIT
Repo
https://github.com/laravel-backpack/crud
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Introduced
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.8.11"
        },
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.0.34"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.4.1
0.5.0
0.5.1
0.5.10
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.17
0.8.18
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.10
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
2.*
2.0.0
2.0.1
2.0.13
2.0.2
2.0.21
2.0.23
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
3.*
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.1.0
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
3.1.21
3.1.22
3.1.23
3.1.24
3.1.25
3.1.33
3.1.34
3.1.35
3.1.36
3.1.37
3.1.38
3.1.41
3.1.42
3.1.43
3.1.44
3.1.45
3.2.0
3.2.1
3.2.10
3.2.12
3.2.2
3.2.3
3.2.4
3.2.7
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.4.0
3.4.1
3.4.2
3.4.21
3.4.22
3.4.23
3.4.24
3.4.25
3.4.26
3.4.27
3.4.28
3.4.29
3.4.3
3.4.30
3.4.31
3.4.32
3.4.33
3.4.34
3.4.4
3.4.5
3.4.6
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.2
3.6.20
3.6.21
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
4.*
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.20
4.0.21
4.0.22
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.54
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.61
4.0.7
4.0.8
4.0.9
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.1.9
5.*
5.0.0
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.10
5.3.11
5.3.12
5.3.13
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
5.4.0
5.4.1
5.4.10
5.4.11
5.4.12
5.4.13
5.4.14
5.4.15
5.4.16
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
5.4.7
5.4.8
5.4.9
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.5.7
5.5.8
5.6.0
5.6.1
6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.1.0
6.1.1
6.1.10
6.1.11
6.1.12
6.1.13
6.1.14
6.1.15
6.1.16
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
6.1.9
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.5.2
6.5.3
6.5.4
6.5.5
6.6.0
6.6.1
6.6.2
6.6.3
6.6.4
6.6.5
6.6.6
6.7.0
6.7.1
6.7.10
6.7.11
6.7.12
6.7.13
6.7.14
6.7.15
6.7.16
6.7.17
6.7.18
6.7.19
6.7.2
6.7.20
6.7.21
6.7.22
6.7.23
6.7.24
6.7.25
6.7.26
6.7.27
6.7.28
6.7.29
6.7.3
6.7.30
6.7.31
6.7.32
6.7.33
6.7.34
6.7.35
6.7.36
6.7.37
6.7.38
6.7.39
6.7.4
6.7.40
6.7.41
6.7.42
6.7.43
6.7.44
6.7.45
6.7.46
6.7.47
6.7.48
6.7.49
6.7.5
6.7.50
6.7.51
6.7.52
6.7.53
6.7.54
6.7.55
6.7.56
6.7.6
6.7.7
6.7.8
6.7.9
6.8.0
6.8.1
6.8.10
6.8.2
6.8.3
6.8.4
6.8.5
6.8.6
6.8.7
6.8.8
6.8.9
7.*
7.0.0
7.0.0-alpha.2
7.0.1
7.0.10
7.0.11
7.0.12
7.0.13
7.0.14
7.0.15
7.0.16
7.0.17
7.0.18
7.0.19
7.0.2
7.0.20
7.0.21
7.0.22
7.0.23
7.0.24
7.0.25
7.0.26
7.0.27
7.0.28
7.0.29
7.0.3
7.0.30
7.0.31
7.0.32
7.0.33
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9
v4.*
v4.0.46

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54175.json"