Detects Laravel Passport instances from 13.0.0 through 13.7.0 where the TokenGuard in authenticateViaBearerToken() fails to distinguish client_credentials grant tokens from user-associated tokens. The JWT subject claim is set to the client ID by the OAuth2 server, but the guard passes it directly to retrieveById() without checking whether it represents a user or client. When client IDs collide with user IDs (integer IDs or MySQL implicit casting of UUIDs), a machine-to-machine token impersonates a real user — reading their data and acting on their behalf. Update to laravel/passport 13.7.1 or later.
Is your app exploitable through CVE-2026-39976?
Scan your domain free