highCVSS 7.6Vulnerability

CVE-2026-54180

## Summary Backpack CRUD's list and read operations correctly apply any query scopes registered via `addClause()` / `addBaseClause()` (e.g. tenant isolation, user ownership). However, the **Update**, **Delete**, and **Reorder** operations bypassed these scopes, fetching records directly from the unscoped model query. An authenticated user who knows or can guess a record's primary key could therefore update, delete, or reorder records that should be invisible to them — a classic IDOR on write paths. Applications that rely on `addBaseClause` for row-level access control (multi-tenancy, per-user data isolation) are affected. ## Impact Any Backpack CRUD panel that uses `addBaseClause` or `addClause` to restrict which rows a user may access is affected on its write operations. An authenticated low-privilege user can modify or delete records belonging to other tenants / users. ## Patches Apply the fixed release for your major version: - **v6**: upgrade to **6.8.14** or later - **v7**: upgrade to **7.0.38** or later The fix ensures Update, Delete, and Reorder all resolve records through the same scoped query used by the read side. ## Workarounds If you cannot upgrade immediately, add explicit `Gate` / `Policy` checks in your `CrudController`'s `update()`, `destroy()`, and `reorder()` methods to verify the authenticated user is permitted to act on the resolved record. ## Credits Reported by Vishal Shukla ([@shukla304](https://github.com/shukla304)).

Properties

ghsa_id
GHSA-vgmv-8xjc-6rch
summary
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
severity
high
cvss_score
7.6
cve_id
CVE-2026-54180
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
is_ghsa_only
false
ghsa_published
2026-08-20T18:38:46Z
source_url
https://github.com/advisories/GHSA-vgmv-8xjc-6rch
ghsa_updated
2026-08-20T18:38:48Z

Related Entities (5)

HAS_WEAKNESS (2)

[Weakness]Authorization Bypass Through User-Controlled Key
[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/backpack/crud

AFFECTS (1)

[Software]composer/backpack/crud

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-54180 (CVSS 7.6) — Ninja Signal Threat Intelligence | Ninja Signal