# Laravel Passport versions 13.x prior to 13.7.1 contain a security policy bypass…

Published: 2026-06-03 · Severity: high
Canonical: https://vorant.io/reports/428fd375-0f78-4322-8177-f0e1b203818f/laravel-passport-versions-13-x-prior-to-13-7-1-contain-a-security-policy-bypass

> Laravel Passport versions 13.x prior to 13.7.1 contain a security policy bypass vulnerability (CVE-2026-39976) allowing attackers to circumvent authentication controls.

The French CERT (CERT-FR) has published an advisory regarding a security policy bypass vulnerability in Laravel Passport, a popular OAuth2 server implementation for Laravel applications. The vulnerability affects all versions in the 13.x branch prior to 13.7.1 and is tracked as CVE-2026-39976.

The flaw allows an attacker to bypass security policies, potentially compromising authentication and authorization mechanisms in affected Laravel applications. While specific technical details of the bypass mechanism are not disclosed in the advisory, the vulnerability has been addressed in version 13.7.1.

Organizations using Laravel Passport should consult the GitHub security advisory GHSA-349c-2h2f-mxf6 and upgrade to version 13.7.1 or later immediately. Given that Laravel Passport handles OAuth2 authentication flows, this vulnerability could impact any application relying on it for API authentication or third-party integrations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-39976

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0682

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/428fd375-0f78-4322-8177-f0e1b203818f/laravel-passport-versions-13-x-prior-to-13-7-1-contain-a-security-policy-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
