CVE-2026-54176 | Laravel-Backpack CRUD up to 6.8.13/7.0.37 Account Info Form postAccountInfoForm session expiration
A vulnerability classified as critical has been found in Laravel-Backpack CRUD up to 6.8.13/7.0.37. Impacted is the function MyAccountController::postAccountInfoForm of the component Account Info Form. The manipulation leads to session expiration.
This vulnerability is documented as CVE-2026-54176. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More