Vulnerabilities

What Is Security Misconfiguration?

A security weakness caused by incorrect or incomplete configuration of applications, servers, databases, or infrastructure. Security misconfiguration is consistently in the OWASP Top 10 (A05) because it is extremely common and often easy to exploit.

In Laravel Applications

The most common Laravel security misconfigurations are: APP_DEBUG=true in production, exposed .env files, publicly accessible Telescope/Ignition/Horizon, missing security headers, default APP_KEY, overly permissive CORS settings, and unprotected admin routes.

Example

Leaving APP_DEBUG=true in production is the most common Laravel security misconfiguration. It exposes environment variables, database credentials, and full stack traces to anyone who triggers an error.

Related Terms

Related Articles

Monitor Your Laravel Application's Security

StackShield continuously checks your Laravel application from the outside, catching security issues before attackers find them.

Start Free Trial