Description
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.
Published: 2026-09-08
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is in the OAuth2 token endpoint of XenForo versions earlier than 2.3.13. By sending an authorization code with empty client_secret and code_verifier parameters, an unauthenticated attacker can bypass both client identity validation and PKCE verification. The attacker then receives a valid token pair and can use it to act as an authenticated user, compromising confidentiality and potentially enabling account takeover. This flaw is due to a logical error in PHP’s truthy evaluation and is classified as CWE‑697.

Affected Systems

All XenForo installations running a version prior to 2.3.13 are affected. The CVE payload does not specify a more granular version range or mention associated add‑ons. Only XenForo is listed as the affected vendor/product.

Risk and Exploitability

The CVSS score of 9.1 places this vulnerability in the critical range. The EPSS score is not available; it is not listed in the CISA KEV catalog. Attackers must first obtain a valid authorization code, which typically requires user interaction or access to the OAuth provider, but once they have it they can exchange it for tokens without any client authentication. The likely attack vector is a web‑based request to the OAuth2 token endpoint, and the vulnerability can be exploited remotely.

Generated by OpenCVE AI on September 8, 2026 at 15:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade XenForo to version 2.3.13 or later to apply the official security fix.
  • If an upgrade cannot be performed immediately, disable or restrict the OAuth2 token endpoint configuration to prevent unauthorized token issuance.
  • Continuously monitor application logs for anomalous token exchange activity and verify that client_secret and code_verifier are being validated by the server.

Generated by OpenCVE AI on September 8, 2026 at 15:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.
Title XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
Weaknesses CWE-697
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T16:01:46.890Z

Reserved: 2026-08-11T19:56:20.006Z

Link: CVE-2026-73309

cve-icon Vulnrichment

Updated: 2026-09-09T16:01:39.863Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:24.913

Modified: 2026-09-11T20:33:42.980

Link: CVE-2026-73309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses