Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-73309: XenForo allows attackers to get login tokens without credentials

CVE-2026-73309 · published 1 month ago
Summary

XenForo versions before 2.3.13 have a weakness in the part that issues OAuth2 tokens. An unauthenticated user can request a token by leaving certain fields blank, letting them log in as any user without proving who they are. Upgrade XenForo to version 2.3.13 or later to close this gap and protect user accounts.

What to do
  • Update xenforo xenforo to version 2.3.13 or later.
Affected software
VendorProductAffected versions
xenforo xenforo < 2.3.13
Original advisory text
XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-697Incorrect Comparison
Timeline
Published8 Sep 2026
Updated9 Oct 2026
First seen8 Sep 2026
Sources
CVE-2026-73309 · MITRE
Track software like this
Free during beta