
CVE-2026-39976 Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/… https://www.cve.org/CVERecord?id=CVE-2026-39976
Post summary
This post announces an authentication bypass vulnerability (CVE‑2026‑39976) in Laravel Passport versions 13.0.0 to 13.7.1 for client_credentials tokens, but no PoC, exploit, or patch details are provided.
