Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-73312: XenForo lets attackers reuse expired login token

CVE-2026-73312 · published 1 month ago
Summary

XenForo versions before 2.3.13 do not properly invalidate refresh tokens after the original login session ends. This lets a malicious user submit the same token repeatedly to obtain new login credentials and stay logged in for the token's full lifespan. Update XenForo to version 2.3.13 or later to close the gap.

What to do
  • Update xenforo xenforo to version 2.3.13 or later.
Affected software
VendorProductAffected versions
xenforo xenforo < 2.3.13
Original advisory text
XenForo < 2.3.13 Refresh Token Replay via Expired Access Token
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-294Authentication Bypass by Capture-replay
Timeline
Published8 Sep 2026
Updated9 Oct 2026
First seen8 Sep 2026
Sources
CVE-2026-73312 · MITRE
Track software like this
Free during beta