Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-73309: XenForo allows attackers to get login tokens without credentials
CVE-2026-73309 · published 1 month ago
Summary
XenForo versions before 2.3.13 have a weakness in the part that issues OAuth2 tokens. An unauthenticated user can request a token by leaving certain fields blank, letting them log in as any user without proving who they are. Upgrade XenForo to version 2.3.13 or later to close this gap and protect user accounts.
What to do
- Update xenforo xenforo to version 2.3.13 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| xenforo | xenforo | < 2.3.13 |
Original advisory text
XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.
References
- https://www.vulncheck.com/advisories/xenforo-authentication-bypass-via-oauth2-to... Third Party Advisory
- https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-an... Release Notes
- https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includ... Release Notes
- https://bombobombone.github.io/posts/cve-2026-73309/ Exploit Third Party Advisory
- https://github.com/BomboBombone/CVE-2026-73309 Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-697Incorrect Comparison
Timeline
Published8 Sep 2026
Updated9 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta