Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccountInfoForm at POST /admin/edit-account-info permits AccountInfoRequest to update backpack_authentication_column(), which is email by default, without requiring current_password or otherwise verifying the account's existing password. An attacker with a temporary authenticated Backpack session can change the account-recovery email and later use the password-reset flow after the original session expires, converting session compromise into persistent account takeover. The same mechanism permits an insider to set a personal recovery address before access is revoked. The separate password-change endpoint is not affected because it verifies old_password. This issue is fixed in versions 6.8.14 and 7.0.38.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized persistent account takeover via email change
Action: Patch promptly
AI Analysis

Impact

The vulnerability allows a user with a temporary authenticated session to change the account’s recovery email address without providing the current password. By setting a new email, the attacker can then trigger the password‑reset flow after the session expires, effectively converting a short‑term session compromise into persistent account takeover.

Affected Systems

The flaw exists in Laravel‑Backpack:CRUD versions 6.0.0 through 6.8.13 and 7.0.0 through 7.0.37. It has been remediated in releases 6.8.14 and 7.0.38, where the account‑info update route now requires password confirmation before altering the email field.

Risk and Exploitability

With a CVSS score of 6.5, the vulnerability is of moderate severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. It is not listed in CISA's KEV catalog. The attack vector requires that the adversary first obtain an authenticated session, but because the email can be changed without a password check, the attacker can subsequently reset the password after the session expires. This path offers persistent access, so while exploitation may depend on initial session acquisition, the potential impact is significant.

Generated by OpenCVE AI on September 20, 2026 at 22:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Backpack‑CRUD to version 6.8.14 or 7.0.38 or later, which enforces a current password check when updating the login email.
  • If upgrading is not immediately feasible, disable or protect the /admin/edit-account-info endpoint in environments where sensitive accounts reside.
  • Validate in custom code or middleware that the current password is required before allowing any change to the login email, and monitor for unauthorized email change attempts in authentication logs.

Generated by OpenCVE AI on September 20, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9fw9-8c49-qch8 Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
History

Tue, 15 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Laravel-backpack
Laravel-backpack crud
Vendors & Products Laravel-backpack
Laravel-backpack crud

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccountInfoForm at POST /admin/edit-account-info permits AccountInfoRequest to update backpack_authentication_column(), which is email by default, without requiring current_password or otherwise verifying the account's existing password. An attacker with a temporary authenticated Backpack session can change the account-recovery email and later use the password-reset flow after the original session expires, converting session compromise into persistent account takeover. The same mechanism permits an insider to set a personal recovery address before access is revoked. The separate password-change endpoint is not affected because it verifies old_password. This issue is fixed in versions 6.8.14 and 7.0.38.
Title backpack/crud: MyAccountController allows changing the login email without a current-password check
Weaknesses CWE-287
CWE-620
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Laravel-backpack Crud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:11:26.656Z

Reserved: 2026-06-11T21:46:52.381Z

Link: CVE-2026-54176

cve-icon Vulnrichment

Updated: 2026-09-14T19:11:22.255Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:52.593

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses