CVE-2026-54180
## Summary Backpack CRUD's list and read operations correctly apply any query scopes registered via `addClause()` / `addBaseClause()` (e.g. tenant isolation, user ownership). However, the **Update**, **Delete**, and **Reorder** operations bypassed these scopes, fetching records directly from the unscoped model query. An authenticated user who knows or can guess a record's primary key could therefore update, delete, or reorder records that should be invisible to them — a classic IDOR on write paths. Applications that rely on `addBaseClause` for row-level access control (multi-tenancy, per-user data isolation) are affected. ## Impact Any Backpack CRUD panel that uses `addBaseClause` or `addClause` to restrict which rows a user may access is affected on its write operations. An authenticated low-privilege user can modify or delete records belonging to other tenants / users. ## Patches Apply the fixed release for your major version: - **v6**: upgrade to **6.8.14** or later - **v7**: upgrade to **7.0.38** or later The fix ensures Update, Delete, and Reorder all resolve records through the same scoped query used by the read side. ## Workarounds If you cannot upgrade immediately, add explicit `Gate` / `Policy` checks in your `CrudController`'s `update()`, `destroy()`, and `reorder()` methods to verify the authenticated user is permitted to act on the resolved record. ## Credits Reported by Vishal Shukla ([@shukla304](https://github.com/shukla304)).
Properties
- ghsa_id
- GHSA-vgmv-8xjc-6rch
- summary
- Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
- severity
- high
- cvss_score
- 7.6
- cve_id
- CVE-2026-54180
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- is_ghsa_only
- false
- ghsa_published
- 2026-08-20T18:38:46Z
- source_url
- https://github.com/advisories/GHSA-vgmv-8xjc-6rch
- ghsa_updated
- 2026-08-20T18:38:48Z
Related Entities (5)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph