Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder operations resolve records from the unscoped model query instead of the query configured through addClause() or addBaseClause(). An authenticated user who knows or guesses an out-of-scope record primary key can therefore modify, delete, or reorder records hidden by tenant, ownership, or other row-level access-control scopes. Applications that do not rely on CRUD query clauses for authorization are not affected by this specific bypass. The fix routes all three write operations through getModelWithCrudPanelQuery(), matching the scoped list and read behavior. This issue is fixed in versions 6.8.14 and 7.0.38.
Published: 2026-09-14
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification, deletion, or reordering of records across tenant boundaries (Authorization bypass)
Action: Patch immediately
AI Analysis

Impact

Backpack:CRUD is a Laravel extension that provides CRUD panels for custom administration tasks. From versions 6.0.0 through 6.8.14 and 7.0.38, the framework’s Update, Delete and Reorder endpoints resolved records using an unscoped model query, ignoring the query clauses added with addClause() or addBaseClause(). As a result, an authenticated user who can determine or guess a primary key belonging to an out‑of‑scope record could modify, delete or reorder that record even though it is protected by tenant, ownership or other row‑level access‑control scopes. The flaw does not grant code execution; it facilitates data tampering, confidentiality loss and privilege escalation across tenant boundaries.

Affected Systems

Vendor: Laravel‑Backpack:CRUD. Vulnerable versions are 6.0.0 through 6.8.14 and 7.0.38. The issue is resolved in 6.8.14 and 7.0.38 and later. Applications that do not rely on CRUD query clauses as an authorization mechanism are not affected by this specific bypass.

Risk and Exploitability

The CVSS score of 7.6 indicates a high‑severity vulnerability that primarily impacts data integrity and confidentiality. The EPSS score is less than 1 %, and the flaw is not listed in the CISA KEV catalog, implying no publicly known exploits yet. Exploitation requires an authenticated session and knowledge of an out‑of‑scope record’s primary key, which limits the risk to users who can obtain such credentials. However, because tenant and ownership boundaries are not respected, an attacker can effectively elevate privileges and compromise data for other tenants.

Generated by OpenCVE AI on September 20, 2026 at 23:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Backpack:CRUD to version 6.8.14 or 7.0.38 or later.
  • Ensure that your application does not rely solely on CRUD query clauses for authorization; if it does, review and strengthen your access‑control logic for update, delete, and reorder actions.
  • Implement an application‑level authorization check that verifies the current user is allowed to manipulate the target record before delegating to Backpack’s CRUD methods, providing temporary protection until the upgrade is applied.

Generated by OpenCVE AI on September 20, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vgmv-8xjc-6rch Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
History

Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Laravel-backpack
Laravel-backpack crud
Vendors & Products Laravel-backpack
Laravel-backpack crud

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder operations resolve records from the unscoped model query instead of the query configured through addClause() or addBaseClause(). An authenticated user who knows or guesses an out-of-scope record primary key can therefore modify, delete, or reorder records hidden by tenant, ownership, or other row-level access-control scopes. Applications that do not rely on CRUD query clauses for authorization are not affected by this specific bypass. The fix routes all three write operations through getModelWithCrudPanelQuery(), matching the scoped list and read behavior. This issue is fixed in versions 6.8.14 and 7.0.38.
Title backpack/crud: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
Weaknesses CWE-639
CWE-863
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Laravel-backpack Crud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:05:38.385Z

Reserved: 2026-06-11T21:46:52.382Z

Link: CVE-2026-54180

cve-icon Vulnrichment

Updated: 2026-09-14T19:20:45.642Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:53.070

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-863

    Incorrect Authorization