VORANT. Threat Intelligence Sign in Get the full feed

Laravel framework versions 12.x and 13.x contain a security policy bypass vulnerability…

high vulnerability

Laravel framework versions 12.x and 13.x contain a security policy bypass vulnerability (CVE-2026-48019) requiring immediate patching to v12.60.0+ or v13.10.0+.

A security policy bypass vulnerability has been identified in the Laravel PHP framework affecting multiple version branches. The flaw impacts Laravel framework versions 12.x prior to 12.60.0 and versions 13.x prior to 13.10.0. An attacker can exploit this vulnerability to circumvent security controls within affected Laravel applications.

The French national CERT (CERT-FR) has published an advisory recommending immediate remediation. Organizations running vulnerable Laravel framework versions should prioritize upgrading to the patched releases. The vendor has addressed the issue in Laravel framework versions 12.60.0 and 13.10.0.

Given Laravel's widespread use in web application development, this vulnerability could affect numerous production systems. Organizations should inventory Laravel deployments, identify vulnerable versions, and apply patches according to their change management processes. The security policy bypass nature of this flaw suggests potential for privilege escalation or unauthorized access in affected applications.

Mentioned in this report

Vulnerabilities CVE-2026-48019

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0670

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free