CVE-2026-73683General

LOWCVSS 9.2 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php. Attackers who obtain a valid, unexpired id_token issued for the same Facebook App ID can submit the captured token to the backend userFromToken() endpoint, bypassing authentication controls because signature, aud, and iss checks pass while no session-bound nonce comparison is performed, resulting in unauthorized access to victim accounts.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-294

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-16)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-15: 1Mentions · 2026-08-16: 2Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-16: 208-1508-16
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-151
General1
2026-08-162
General1Patch1
Full discourse3 posts
  • Shota Zaizen (財前 匠汰)@z41zen
    General

    僕の後輩らしい🫣(ほんと) CVE取れたので脆弱性の説明と学習したこと リプレイ攻撃の脆弱性 - CVE-2026-73683 -|meihao550 https://zenn.dev/meihao550/articles/a1561a73696d77 #zenn

    Post summary

    The post notes that a junior colleague found CVE-2026-73683, a replay‑attack vulnerability, and provided a link to an article explaining it, but offers no details on exploits, patches, or active exploitation.

    05065437.3K
    173 followersView on X
  • yousukezan@yousukezan
    General

    CVE取れたので脆弱性の説明と学習したこと リプレイ攻撃の脆弱性 - CVE-2026-73683 -|meihao550 https://zenn.dev/meihao550/articles/a1561a73696d77 #zenn

    Post summary

    The author announces having CID CVE-2026‑73683 and notes it is a replay attack vulnerability, citing an explanatory article where they share their findings and learning.

    05016103.5K
    15.0K followersView on X
  • kmkz@kmkz_security
    Patch

    #CVE-2026-73683: #Laravel Socialite < 5.29.0 OIDC token replay. Valid signature/issuer. > No nonce validation. Capture a victim Facebook "id_token", replay it against the same App ID, get the victim identity back , "et voilà !" Just missing transaction binding (no jwt forgery). Fix: "hash_equals($expectedNonce, $data['nonce'])" Technical details / patch : https://github.com/laravel/socialite/pull/789?utm_source=chatgpt.com

    Post summary

    Laravel Socialite <5.29.0 suffers from OIDC token replay due to missing nonce validation; the issue is mitigated by adding a nonce check and a pull request patch is available.

    010201.2K
    19.8K followersView on X

Explore more