Количество 3
Количество 3
CVE-2026-39976
Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value to retrieveById() without validating it's actually a user identifier, potentially resolving an unrelated real user. Any machine-to-machine token can inadvertently authenticate as an actual user. This vulnerability is fixed in 13.7.1.
GHSA-349c-2h2f-mxf6
Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials Tokens
BDU:2026-05283
Уязвимость функции retrieveById() пакета для реализации сервера OAuth2 Laravel Passport, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-39976 Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value to retrieveById() without validating it's actually a user identifier, potentially resolving an unrelated real user. Any machine-to-machine token can inadvertently authenticate as an actual user. This vulnerability is fixed in 13.7.1. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
GHSA-349c-2h2f-mxf6 Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials Tokens | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
BDU:2026-05283 Уязвимость функции retrieveById() пакета для реализации сервера OAuth2 Laravel Passport, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.1 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу