Backpack CRUD's list and read operations correctly apply any query scopes
registered via addClause() / addBaseClause() (e.g. tenant isolation, user
ownership). However, the Update, Delete, and Reorder operations
bypassed these scopes, fetching records directly from the unscoped model query.
An authenticated user who knows or can guess a record's primary key could therefore update, delete, or reorder records that should be invisible to them — a classic IDOR on write paths.
Applications that rely on addBaseClause for row-level access control
(multi-tenancy, per-user data isolation) are affected.
Any Backpack CRUD panel that uses addBaseClause or addClause to restrict
which rows a user may access is affected on its write operations.
An authenticated low-privilege user can modify or delete records belonging to
other tenants / users.
Apply the fixed release for your major version:
The fix ensures Update, Delete, and Reorder all resolve records through the same scoped query used by the read side.
If you cannot upgrade immediately, add explicit Gate / Policy checks in your
CrudController's update(), destroy(), and reorder() methods to verify
the authenticated user is permitted to act on the resolved record.
Reported by Vishal Shukla (@shukla304).
{
"cwe_ids": [
"CWE-639",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-20T18:38:46Z",
"nvd_published_at": null,
"severity": "HIGH"
}