Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-73311: XenForo < 2.3.13 lets reused login codes grant access

CVE-2026-73311 · published 1 month ago
Summary

Versions of XenForo before 2.3.13 do not mark single‑use login codes as used, so an attacker who captures one of those codes can submit it again and obtain a valid access key for the same user. This lets the attacker act as that user without permission. Update XenForo to version 2.3.13 or later, or apply the vendor’s patch, to stop the reuse.

What to do
  • Update xenforo xenforo to version 2.3.13 or later.
Affected software
VendorProductAffected versions
xenforo xenforo < 2.3.13
Original advisory text
XenForo < 2.3.13 OAuth2 Authorization Code Reuse
XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token issuance to receive an independent token pair for the same user and scopes, bypassing the single-use guarantee of the OAuth2 authorization code flow.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-294Authentication Bypass by Capture-replay
Timeline
Published8 Sep 2026
Updated9 Oct 2026
First seen8 Sep 2026
Sources
CVE-2026-73311 · MITRE
Track software like this
Free during beta