CVE-2026-54175 | Laravel-Backpack backpackcrud up to 6.8.10/7.0.33 Account Info Form MyAccountController.php postAccountInfoForm Request access control

SecurityVulns

A vulnerability was found in Laravel-Backpack backpackcrud up to 6.8.10/7.0.33. It has been declared as critical. The affected element is the function MyAccountController::postAccountInfoForm of the file src/app/Http/Controllers/MyAccountController.php of the component Account Info Form. Such manipulation of the argument Request leads to improper access controls.

This vulnerability is referenced as CVE-2026-54175. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More