Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and MorphMany handling through attachManyRelation during CRUD create and update operations accepts submitted child primary keys without consistently restricting updates to records belonging to the current parent or permitted by the developer-defined relation scope. An authenticated low-privilege administrator who can edit a parent form exposing an affected multiple-relation field can cause unrelated child records to be reassigned, detached, nulled, or deleted across ownership or tenant boundaries. Exploitation requires related records that should not be attachable or removable by that administrator and the absence of additional application-level authorization around submitted relation values. This issue is distinct from earlier direct main-entity CRUD scoping fixes because it affects secondary models modified by relationship-saving logic. This issue is fixed in versions 6.8.15 and 7.0.47.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation through cross‑tenant record re‑parenting via an IDOR flaw in relationship management
Action: Patch Immediately
AI Analysis

Impact

The flaw allows an authenticated low‑privilege administrator to reassign, detach, nullify, or delete child records that belong to a different parent or tenant by submitting arbitrary child record identifiers to the attachManyRelation operation. This bypasses the intended restriction of modifying only records that belong to the current parent or are permitted by developer‑defined scope, enabling an attacker to violate data isolation and compromise the integrity of unrelated data. The weakness is a Missing Authorization vulnerability (CWE‑862), giving access to cross‑tenant data manipulation that can affect confidentiality, integrity, and availability of the application data.

Affected Systems

Laravel-Backpack:CRUD versions 6.0.0 through 6.8.15 and 7.0.47 are affected. The fix was released in version 6.8.15 and 7.0.47 and later releases. Vendors other than Backpack:CRUD are not listed as affected.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate severity, and the vulnerability is not yet listed in CISA's KEV catalog. The EPSS score is reported as <1%, indicating a very low but nonzero exploitation probability. The attack requires a legitimate authenticated session of a low‑privilege administrator that can edit a parent form exposing the vulnerable multi‑relation field, so the vector is local web application via feasible privilege escalation rather than remote exploitation. The exploit conditions rely solely on the lack of additional application‑level authorization around submitted relation values, making the vulnerability highly actionable within a compromised or weakly secured administrative environment.

Generated by OpenCVE AI on September 20, 2026 at 22:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Backpack:CRUD to version 6.8.15 or 7.0.47 (or later) on all installations, following the official release notes and security advisory GHSA-42vx-43vc-x6pr.
  • If an immediate upgrade is not possible, disable the attachManyRelation functionality for low‑privilege administrators, or add custom middleware that enforces tenant boundaries and validates that submitted child records belong to the current parent before processing the relationship update.
  • Add application‑level authorization logic or tightly scoped middleware to ensure that only permitted child records may be attached, detached, nulled, or deleted, preventing cross‑tenant or cross‑parent data manipulation.

Generated by OpenCVE AI on September 20, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-42vx-43vc-x6pr Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation
History

Tue, 15 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Laravel-backpack
Laravel-backpack crud
Vendors & Products Laravel-backpack
Laravel-backpack crud

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and MorphMany handling through attachManyRelation during CRUD create and update operations accepts submitted child primary keys without consistently restricting updates to records belonging to the current parent or permitted by the developer-defined relation scope. An authenticated low-privilege administrator who can edit a parent form exposing an affected multiple-relation field can cause unrelated child records to be reassigned, detached, nulled, or deleted across ownership or tenant boundaries. Exploitation requires related records that should not be attachable or removable by that administrator and the absence of additional application-level authorization around submitted relation values. This issue is distinct from earlier direct main-entity CRUD scoping fixes because it affects secondary models modified by relationship-saving logic. This issue is fixed in versions 6.8.15 and 7.0.47.
Title backpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Laravel-backpack Crud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:11:21.485Z

Reserved: 2026-06-24T18:49:56.207Z

Link: CVE-2026-57570

cve-icon Vulnrichment

Updated: 2026-09-14T18:10:45.594Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:57.180

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-57570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses