Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDisk in src/app/Models/Traits/HasUploadFields.php trusts disk-relative paths from clear_<attribute>[] and passes them to Storage::disk()->delete without confirming that the paths are persisted on the current model record. An authenticated user with Update access to a CRUD using this mutator through src/app/Models/Traits/CrudTrait.php can delete another record's attachment, a shared asset, or another operational file on the configured disk by submitting its path. The newer MultipleFiles uploader is not affected because it intersects requested deletions with the record's persisted file list. This flaw does not permit reading the deleted files. The 5.x line remains affected through its final releases. This issue is fixed in versions 6.8.12 and 7.0.35.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Integrity Impact
Action: Apply Patch
AI Analysis

Impact

Backpack CRUD, part of Laravel's Backpack, builds admin panels with CRUD operations. In vulnerable releases older than version 6.8.12 (and 7.0.35) and the final 5.x releases, the HasUploadFields::uploadMultipleFilesToDisk method accepts disk‑relative paths supplied via the clear_<attribute>[] mutator and forwards them to Storage::disk()->delete without confirming that the paths belong to the current model. An attacker who can authenticate and has Update access to a CRUD that uses this mutator can submit any file path on the configured disk; the system will delete that file, allowing removal of another record’s attachment, a shared asset, or other operational files. The newer MultipleFiles uploader mitigates this by intersecting the requested deletions with the persisted file list, and the flaw does not permit reading deleted files.

Affected Systems

Laravel Backpack CRUD versions prior to 6.8.12 and 7.0.35 are susceptible to this issue, as is the 5.x branch through its final releases. Any deployment that installs these vulnerable releases on a Laravel environment with an update‑permitted CRUD interface faces the risk. The affected artifact is the src/app/Models/Traits/HasUploadFields.php trait, which is commonly used in Backpack CRUD projects to manage file uploads. The same vulnerability affects any user‑credential that can exercise Update permissions on a CRUD that uses the HasUploadFields mutator.

Risk and Exploitability

The CVSS score of 8.1 classifies this vulnerability as high severity, reflecting that an authenticated attacker with Update privileges can remove arbitrary files. The EPSS score indicates an exploitation probability of less than 1 %, suggesting a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need only a valid user session with Update rights, which is common in many administration interfaces. While deletion does not provide code execution, it compromises data integrity and availability. The issue remains exploitable until the vulnerable package is updated or mitigated.

Generated by OpenCVE AI on September 20, 2026 at 22:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Laravel Backpack CRUD to version 6.8.12 or later, or 7.0.35 or later.
  • Restrict Update permissions on CRUD interfaces that handle file uploads to trusted roles.
  • Validate any file deletion requests against the record's persisted file list or reject arbitrary disk‑relative paths.

Generated by OpenCVE AI on September 20, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8xjm-wqrp-2f25 Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Laravel-backpack
Laravel-backpack crud
Vendors & Products Laravel-backpack
Laravel-backpack crud

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDisk in src/app/Models/Traits/HasUploadFields.php trusts disk-relative paths from clear_<attribute>[] and passes them to Storage::disk()->delete without confirming that the paths are persisted on the current model record. An authenticated user with Update access to a CRUD using this mutator through src/app/Models/Traits/CrudTrait.php can delete another record's attachment, a shared asset, or another operational file on the configured disk by submitting its path. The newer MultipleFiles uploader is not affected because it intersects requested deletions with the record's persisted file list. This flaw does not permit reading the deleted files. The 5.x line remains affected through its final releases. This issue is fixed in versions 6.8.12 and 7.0.35.
Title backpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
Weaknesses CWE-22
CWE-285
CWE-639
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Laravel-backpack Crud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:03:33.705Z

Reserved: 2026-06-11T21:46:52.382Z

Link: CVE-2026-54178

cve-icon Vulnrichment

Updated: 2026-09-16T16:03:29.887Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:52.917

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key