PKSA-wb9h-r8p2-f7xj Security Advisory
-
[MEDIUM] Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
PKSA-wb9h-r8p2-f7xj CVE-2026-54176 GHSA-9fw9-8c49-qch8
Affected package: backpack/crud
Affected version: >=7.0.0,<7.0.38|>=6.0.0,<6.8.14
Reported by:
GitHub