CVE-2026-54176
backpack/crud: MyAccountController allows changing the login email without a current-password check
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccountInfoForm at POST /admin/edit-account-info permits AccountInfoRequest to update backpack_authentication_column(), which is email by default, without requiring current_password or otherwise verifying the account's existing password. An attacker with a temporary authenticated Backpack session can change the account-recovery email and later use the password-reset flow after the original session expires, converting session compromise into persistent account takeover. The same mechanism permits an insider to set a personal recovery address before access is revoked. The separate password-change endpoint is not affected because it verifies old_password. This issue is fixed in versions 6.8.14 and 7.0.38.
| CWE | CWE-287 CWE-620 |
| Vendor | laravel-backpack |
| Product | crud |
| Published | Sep 14, 2026 |
| Last Updated | Sep 14, 2026 |
Get instant alerts for laravel-backpack crud
Be the first to know when new medium vulnerabilities affecting laravel-backpack crud are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N