CVE-2026-54180

high

Description

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder operations resolve records from the unscoped model query instead of the query configured through addClause() or addBaseClause(). An authenticated user who knows or guesses an out-of-scope record primary key can therefore modify, delete, or reorder records hidden by tenant, ownership, or other row-level access-control scopes. Applications that do not rely on CRUD query clauses for authorization are not affected by this specific bypass. The fix routes all three write operations through getModelWithCrudPanelQuery(), matching the scoped list and read behavior. This issue is fixed in versions 6.8.14 and 7.0.38.

References

https://github.com/Laravel-Backpack/CRUD/security/advisories/GHSA-vgmv-8xjc-6rch

https://github.com/Laravel-Backpack/CRUD/releases/tag/7.0.38

https://github.com/Laravel-Backpack/CRUD/releases/tag/6.8.14

https://github.com/Laravel-Backpack/CRUD/pull/5994

https://github.com/Laravel-Backpack/CRUD/pull/5991

https://github.com/Laravel-Backpack/CRUD/commit/dd25c2086b8ea2cb765993b65876c66ab824eef0

https://github.com/Laravel-Backpack/CRUD/commit/76c3a6e50e3fbd6d5f633208da5b04acb8322969

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77717

Details

Source: Mitre, NVD

Published: 2026-09-14

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:C/A:P

Severity: High

CVSS v3

Base Score: 7.6

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Severity: High

EPSS

EPSS: 0.00329