CVE-2026-54175
## Summary The `MyAccountController::postAccountInfoForm` action bound to `POST /admin/edit-account-info` calls `$this->guard()->user()->update($request->except(['_token']))`. Because the controller uses `except(['_token'])` rather than `$request->validated()` or the restricted keys defined in `AccountInfoRequest::validationData()`, **any column present in the user model's `$fillable` array is mass-assigned from the request**, including `password`. Backpack ships a separate `POST /admin/change-password` route (`postChangePasswordForm`) that requires `old_password` verification via `ChangePasswordRequest::withValidator`. The `edit-account-info` endpoint silently bypasses that security control. For the default Laravel 11 `App\Models\User` model — which Backpack's installer and documentation use as the canonical admin user model — `$fillable` is `['name','email','password']`. The `password` cast is `hashed`, so a plaintext `password=…` form field is automatically hashed and persisted. Any attacker holding an authenticated Backpack session (session theft, stolen cookies, XSS, public-terminal residual session) can permanently take over the account by issuing one POST that includes `password=<attacker_value>`, with no knowledge of the victim's current password. This converts time-limited, session-bound access into persistent account takeover. ## Vulnerable code `src/app/Http/Controllers/MyAccountController.php:38` ```php public function postAccountInfoForm(AccountInfoRequest $request) { $result = $this->guard()->user()->update($request->except(['_token'])); ... } ``` `src/app/Http/Requests/AccountInfoRequest.php` `validationData()` only narrows what gets validated (`name`, email column) — it does NOT narrow what is later saved. ## Impact 1. **Persistent account takeover after session theft.** An adversary holding any authenticated Backpack session cookie (XSS, malware, stolen device, shared workstation) can rewrite the victim's password and retain access i
Properties
- ghsa_id
- GHSA-xpv2-hrfc-hw62
- summary
- Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment
- severity
- high
- cvss_score
- 7.6
- cve_id
- CVE-2026-54175
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- is_ghsa_only
- false
- ghsa_published
- 2026-08-20T18:38:26Z
- source_url
- https://github.com/advisories/GHSA-xpv2-hrfc-hw62
- ghsa_updated
- 2026-08-20T18:38:28Z
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph