Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-73311: XenForo < 2.3.13 lets reused login codes grant access
CVE-2026-73311 · published 1 month ago
Summary
Versions of XenForo before 2.3.13 do not mark single‑use login codes as used, so an attacker who captures one of those codes can submit it again and obtain a valid access key for the same user. This lets the attacker act as that user without permission. Update XenForo to version 2.3.13 or later, or apply the vendor’s patch, to stop the reuse.
What to do
- Update xenforo xenforo to version 2.3.13 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| xenforo | xenforo | < 2.3.13 |
Original advisory text
XenForo < 2.3.13 OAuth2 Authorization Code Reuse
XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token issuance to receive an independent token pair for the same user and scopes, bypassing the single-use guarantee of the OAuth2 authorization code flow.
References
- https://bombobombone.github.io/posts/cve-2026-73311/ Exploit Third Party Advisory
- https://github.com/BomboBombone/CVE-2026-73311 Exploit Third Party Advisory
- https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-an... Release Notes
- https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includ... Release Notes
- https://www.vulncheck.com/advisories/xenforo-oauth2-authorization-code-reuse Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-294Authentication Bypass by Capture-replay
Timeline
Published8 Sep 2026
Updated9 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta