CRITICAL 9.1 NVD
CVE-2026-73309
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token p
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.
Affected Products
- xenforo/xenforo
References
- https://bombobombone.github.io/posts/cve-2026-73309/
- https://github.com/BomboBombone/CVE-2026-73309
- https://www.vulncheck.com/advisories/xenforo-authentication-bypass-via-oauth2-token-endpoi
- https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-and-media-ga
- https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includes-securit
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-08 via NVD. Affected: xenforo/xenforo.
Risk Timeline
CVE Disclosed2026-09-08 · 2 days ago
Remediation Resources
Official Advisory
bombobombone.github.io/posts/cve-2026-73309/Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-73311 | XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability | CRITICAL | 9.1 |
| CVE-2026-73312 | XenForo before 2.3.13 contains a refresh token replay vulnerability that allows | CRITICAL | 9.1 |
| CVE-2026-73314 | XenForo before 2.3.13 contains a signature verification logic error in the PayPa | HIGH | 8.7 |
| CVE-2026-73316 | XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST | HIGH | 8.7 |
| CVE-2026-74239 | XenForo before 2.3.13 contains a path traversal vulnerability in the style archi | HIGH | 8.6 |
| CVE-2026-73310 | XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoin | HIGH | 8.2 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.