Description
XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token issuance to receive an independent token pair for the same user and scopes, bypassing the single-use guarantee of the OAuth2 authorization code flow.
Published: 2026-09-08
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized token issuance via OAuth2 code reuse
Action: Immediate patch
AI Analysis

Impact

The vulnerability stems from XenForo’s failure to invalidate or mark OAuth2 authorization codes as consumed after the first token issuance. Consequently, attackers who obtain a previously used authorization code can submit it again and receive an additional token pair that grants access to the same user and scopes. This bypasses the single-use guarantee of the OAuth2 authorization code flow, potentially exposing any data or actions that the token scopes permit.

Affected Systems

The affected product is XenForo forum software, specifically all versions prior to 2.3.13. This includes the 2.2.x and 2.3.x series up to and including 2.3.12.

Risk and Exploitability

The CVSS score of 9.1 classifies this flaw as critical. Though an EPSS score is not available, the fact that it is not listed in the CISA KEV catalog does not diminish the risk. The vulnerability can be exploited remotely by submitting a known or intercepted authorization code through the OAuth2 endpoint, allowing an attacker to gain unauthorized access to the victim’s resources. Because the attack requires only the ability to reuse a code, and the code may be harvested via phishing or interception, the likelihood of exploitation remains significant for exposed installations.

Generated by OpenCVE AI on September 8, 2026 at 15:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade XenForo to version 2.3.13 or later, which properly invalidates OAuth2 authorization codes after use.
  • If an upgrade cannot be performed immediately, consider disabling OAuth2 authentication for public exposure or restricting the grant types to eliminate code reuse possibilities.
  • Audit and enforce strict consumption checks in any custom OAuth2 implementations, ensuring that each code is single-use and that failing to consume a code results in immediate invalidation of the associated token pair.

Generated by OpenCVE AI on September 8, 2026 at 15:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token issuance to receive an independent token pair for the same user and scopes, bypassing the single-use guarantee of the OAuth2 authorization code flow.
Title XenForo < 2.3.13 OAuth2 Authorization Code Reuse
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T15:03:13.927Z

Reserved: 2026-08-11T19:56:20.007Z

Link: CVE-2026-73311

cve-icon Vulnrichment

Updated: 2026-09-10T13:50:53.211Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:25.220

Modified: 2026-09-11T20:30:43.397

Link: CVE-2026-73311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay