highCVSS 7.6Vulnerability

CVE-2026-54175

## Summary The `MyAccountController::postAccountInfoForm` action bound to `POST /admin/edit-account-info` calls `$this->guard()->user()->update($request->except(['_token']))`. Because the controller uses `except(['_token'])` rather than `$request->validated()` or the restricted keys defined in `AccountInfoRequest::validationData()`, **any column present in the user model's `$fillable` array is mass-assigned from the request**, including `password`. Backpack ships a separate `POST /admin/change-password` route (`postChangePasswordForm`) that requires `old_password` verification via `ChangePasswordRequest::withValidator`. The `edit-account-info` endpoint silently bypasses that security control. For the default Laravel 11 `App\Models\User` model — which Backpack's installer and documentation use as the canonical admin user model — `$fillable` is `['name','email','password']`. The `password` cast is `hashed`, so a plaintext `password=…` form field is automatically hashed and persisted. Any attacker holding an authenticated Backpack session (session theft, stolen cookies, XSS, public-terminal residual session) can permanently take over the account by issuing one POST that includes `password=<attacker_value>`, with no knowledge of the victim's current password. This converts time-limited, session-bound access into persistent account takeover. ## Vulnerable code `src/app/Http/Controllers/MyAccountController.php:38` ```php public function postAccountInfoForm(AccountInfoRequest $request) { $result = $this->guard()->user()->update($request->except(['_token'])); ... } ``` `src/app/Http/Requests/AccountInfoRequest.php` `validationData()` only narrows what gets validated (`name`, email column) — it does NOT narrow what is later saved. ## Impact 1. **Persistent account takeover after session theft.** An adversary holding any authenticated Backpack session cookie (XSS, malware, stolen device, shared workstation) can rewrite the victim's password and retain access i

Properties

ghsa_id
GHSA-xpv2-hrfc-hw62
summary
Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment
severity
high
cvss_score
7.6
cve_id
CVE-2026-54175
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
is_ghsa_only
false
ghsa_published
2026-08-20T18:38:26Z
source_url
https://github.com/advisories/GHSA-xpv2-hrfc-hw62
ghsa_updated
2026-08-20T18:38:28Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Unverified Password Change

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/backpack/crud

AFFECTS (1)

[Software]composer/backpack/crud

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-54175 (CVSS 7.6) — Ninja Signal Threat Intelligence | Ninja Signal