Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm in src/app/Http/Controllers/MyAccountController.php at POST /admin/edit-account-info passes request data from $request->except(['_token']) to the user model instead of restricting updates to fields accepted by AccountInfoRequest::validationData(). An attacker with an authenticated Backpack session can therefore mass-assign password, the authentication column, or other deployment-specific fillable attributes. With the default Laravel 11 user model, a submitted plaintext password is automatically hashed and persisted, converting temporary session access into persistent account takeover without the old_password check enforced by the separate password-change route. Changing the authentication email can also enable later password-reset takeover, while additional fillable security attributes can permit deployment-specific privilege escalation or security-control changes. This issue is fixed in versions 6.8.11 and 7.0.34.
Published: 2026-09-14
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Account Takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability enables an authenticated Backpack admin to modify a user’s password, authentication column, or other fillable attributes by sending a POST to /admin/edit-account-info. The controller passes all unchecked request fields except the CSRF token directly to the user model, bypassing the validation rules defined in AccountInfoRequest. As a result, a plaintext password sent by the attacker is automatically hashed and stored, turning a temporary session into a persistent account takeover without requiring the old password. The flaw also allows changing the authentication email, potentially enabling later password‑reset hijacking, and opens the door for deployment‑specific privilege escalation if other sensitive fields are writable. The vulnerability is mitigated in Backpack:CRUD 6.8.11 and 7.0.34.

Affected Systems

All installations of Laravel‑Backpack:CRUD that use MyAccountController and are running an earlier version than 6.8.11 or 7.0.34 are affected. Users of the default Laravel 11 user model that automatically hashes incoming plaintext passwords are especially vulnerable because the change is persisted without requiring the old password.

Risk and Exploitability

The CVSS score of 7.6 indicates a high impact vulnerability. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The issue is not currently listed in CISA KEV, but the flaw still permits account takeover as soon as an attacker obtains an authenticated session. The attack path requires only legitimate credentials and leverages an unchecked mass assignment route, making exploitation straightforward for anyone who can otherwise access the admin area.

Generated by OpenCVE AI on September 20, 2026 at 23:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Laravel‑Backpack:CRUD to version 6.8.11 or higher, or 7.0.34 or higher, which applies the proper validation checks for account changes.
  • Remove or disable any older instances of Backpack:CRUD from the codebase to eliminate the vulnerable endpoint.
  • Audit the application for other models that may use mass assignment and enforce explicit field whitelisting or strong parameter filtering, ensuring that password and critical configuration changes require proper authentication and authorization checks.

Generated by OpenCVE AI on September 20, 2026 at 23:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xpv2-hrfc-hw62 Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment
History

Tue, 15 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Laravel-backpack
Laravel-backpack crud
Vendors & Products Laravel-backpack
Laravel-backpack crud

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm in src/app/Http/Controllers/MyAccountController.php at POST /admin/edit-account-info passes request data from $request->except(['_token']) to the user model instead of restricting updates to fields accepted by AccountInfoRequest::validationData(). An attacker with an authenticated Backpack session can therefore mass-assign password, the authentication column, or other deployment-specific fillable attributes. With the default Laravel 11 user model, a submitted plaintext password is automatically hashed and persisted, converting temporary session access into persistent account takeover without the old_password check enforced by the separate password-change route. Changing the authentication email can also enable later password-reset takeover, while additional fillable security attributes can permit deployment-specific privilege escalation or security-control changes. This issue is fixed in versions 6.8.11 and 7.0.34.
Title backpack/crud: Unverified password change in MyAccountController via mass assignment
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Laravel-backpack Crud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:12:27.005Z

Reserved: 2026-06-11T21:46:52.381Z

Link: CVE-2026-54175

cve-icon Vulnrichment

Updated: 2026-09-14T18:12:22.010Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:52.430

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-620

    Unverified Password Change