Back Redpacketsecurity CVE Alert: CVE-2026-73312 – XenForo
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token’s full lifetime.
**Risk verdict:** This is a high-impact authentication weakness requiring prompt remediation, but the available intelligence does not indicate active exploitation or warrant emergency handling solely on that basis.
**Why this matters:** Successful abuse could provide durable access to user accounts and enable unauthorised reading or modification of forum content, private messages, profiles, and administrative data. The principal attacker objectives are account takeover, privilege escalation through compromised administrators, data theft, and use of the platform as a launch point for fraud or reputational damage. SSVC assesses technical impact as total, while exploitation is currently recorded as none and automation as no; KEV, EPSS, and PoC status are not provided.
**Most likely attack path:** The attack is network-based and requires no privileges or user interaction, but high attack complexity suggests the adversary must first obtain a valid refresh token and time or reproduce the relevant token state. Scope is unchanged, so direct impact remains within the application’s authority boundary, although administrator compromise could expose the wider organisation through trusted accounts.
**Who is most exposed:** Internet-facing community, membership, support, and customer-portal deployments with long-lived sessions or administrator accounts are the main concern, particularly sites permitting third-party add-ons and extensive private content.
Alert on repeated refresh requests using the same token identifier or fingerprint.
Hunt for token issuance after parent-token expiry.
Review unusual concurrent sessions, geographies, devices, and administrator actions.
Correlate refresh activity with account takeover indicators.
Mitigation and prioritisation:
Apply the vendor security update promptly, including compatible add-ons and extensions.
Revoke active refresh tokens and force reauthentication after patching.
Temporarily shorten token lifetimes and strengthen MFA for privileged users.
Test token-consumption and expiry behaviour in staging before change-window deployment.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
