Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-73312: XenForo lets attackers reuse expired login token
CVE-2026-73312 · published 1 month ago
Summary
XenForo versions before 2.3.13 do not properly invalidate refresh tokens after the original login session ends. This lets a malicious user submit the same token repeatedly to obtain new login credentials and stay logged in for the token's full lifespan. Update XenForo to version 2.3.13 or later to close the gap.
What to do
- Update xenforo xenforo to version 2.3.13 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| xenforo | xenforo | < 2.3.13 |
Original advisory text
XenForo < 2.3.13 Refresh Token Replay via Expired Access Token
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
References
- https://www.vulncheck.com/advisories/xenforo-refresh-token-replay-via-expired-ac... Third Party Advisory
- https://bombobombone.github.io/posts/cve-2026-73312/ Exploit Third Party Advisory
- https://github.com/BomboBombone/CVE-2026-73312 Exploit Third Party Advisory
- https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-an... Release Notes
- https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includ... Release Notes
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-294Authentication Bypass by Capture-replay
Timeline
Published8 Sep 2026
Updated9 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta