HIGHVulnerability

CVE-2026-73683

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php. Attackers who obtain a valid, unexpired id_token issued for the same Facebook App ID can submit the captured token to the backend userFromToken() endpoint, bypassing authentication controls because signature, aud, and iss checks pass while no session-bound nonce comparison is performed, resulting in unauthorized access to victim accounts.

Properties

severity
HIGH
score
8.1
cve_id
CVE-2026-73683
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-14T22:17:11.550
last_modified
2026-08-18T03:16:40.690

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass by Capture-replay

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73683 — Ninja Signal Threat Intelligence | Ninja Signal