Multiple OAuth Vulnerabilities Discovered in XenForo

Multiple OAuth Vulnerabilities Discovered in XenForo

First seen 8 Sep 2026, 15:46 UTC Redpacketsecurity 57.9

Article Content

Browse articles
ThreatCluster

XenForo versions prior to 2.3.13 are affected by three critical vulnerabilities: CVE-2026-73311, CVE-2026-73312, and CVE-2026-73309. These vulnerabilities include an OAuth2 authorization code reuse flaw, a refresh token replay issue, and an authentication bypass vulnerability, respectively. Attackers can exploit these weaknesses to gain unauthorized access to user accounts, potentially leading to account takeovers and data theft. The vulnerabilities are network-based and require no prior user interaction, making them particularly dangerous for internet-facing community and support portals. Although the vulnerabilities have been disclosed, there is currently no evidence of active exploitation. Administrators are advised to apply the vendor's security updates promptly and review their OAuth integrations for potential misuse. The vulnerabilities were published on 2026-09-08.

Key Points: • XenForo versions before 2.3.13 have three critical vulnerabilities. • Attackers can exploit these flaws for unauthorized access and account takeover. • No active exploitation has been confirmed, but immediate patching is recommended.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-73311 published
XenForo OAuth2 authorization code reuse vulnerability disclosed, allowing token pair exploitation.
Redpacketsecurity
2026-09-08
CVE-2026-73312 published
XenForo refresh token replay vulnerability disclosed, enabling unauthorized persistent access.
Redpacketsecurity
2026-09-08
CVE-2026-73309 published
XenForo authentication bypass vulnerability disclosed, allowing token pair acquisition without validation.
Redpacketsecurity