All verified exploits

CVE-2026-39976 Passport Client Credentials User Impersonation

Pentest high Laravel Added cve-verified-cve-2026-39976

Detects Laravel Passport instances from 13.0.0 through 13.7.0 where the TokenGuard in authenticateViaBearerToken() fails to distinguish client_credentials grant tokens from user-associated tokens. The JWT subject claim is set to the client ID by the OAuth2 server, but the guard passes it directly to retrieveById() without checking whether it represents a user or client. When client IDs collide with user IDs (integer IDs or MySQL implicit casting of UUIDs), a machine-to-machine token impersonates a real user — reading their data and acting on their behalf. Update to laravel/passport 13.7.1 or later.

Related Laravel exploits

Is your app exploitable through CVE-2026-39976?

Scan your domain free