CVE-2026-73683 | Laravel Socialite up to 5.28.x Facebook Provider FacebookProvider.php getUserByOIDCToken improper authorization

SecurityVulns

A vulnerability categorized as critical has been discovered in Laravel Socialite up to 5.28.x. The affected element is the function getUserByOIDCToken of the file FacebookProvider.php of the component Facebook Provider. The manipulation results in improper authorization.

This vulnerability is reported as CVE-2026-73683. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More