Description
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
Published: 2026-09-08
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Persistent Unauthorized Access via Replayable Refresh Tokens
Action: Patch Immediately
AI Analysis

Impact

XenForo before version 2.3.13 has a flaw in the refresh‑token flow that fails to mark tokens as consumed once the parent access token expires. This allows an adversary to submit the same refresh token repeatedly and receive new token pairs, granting continued and independent authenticated access for the token’s full lifetime.

Affected Systems

The issue affects all XenForo deployments running any version earlier than 2.3.13. All users and administrators running these affected builds are at risk until a patch or newer version is applied.

Risk and Exploitability

With a CVSS score of 9.1 the vulnerability is considered Critical. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of exploit data does not reduce the severity. Based on the description, it is inferred that attackers must already possess a valid refresh token, which could be obtained through credential compromise, phishing, or other means. Based on the description, it is inferred that from there the attacker may repeatedly call the refresh endpoint over the network, subject to the tolerance of server resources. Based on the description, it is inferred that this remote exploitation path could be executed by a determined attacker without additional privilege escalation.

Generated by OpenCVE AI on September 8, 2026 at 15:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to XenForo 2.3.13 or a later release where the refresh‑token handling has been fixed.
  • Update all add‑ons and extensions to their most recent versions, as some may reuse the same token logic and are included in the vendor’s release notes.
  • Immediately revoke or rotate existing refresh tokens for all users after patching to remove stale tokens that could be reused by an attacker.

Generated by OpenCVE AI on September 8, 2026 at 15:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
Title XenForo < 2.3.13 Refresh Token Replay via Expired Access Token
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T01:07:34.155Z

Reserved: 2026-08-11T19:56:20.007Z

Link: CVE-2026-73312

cve-icon Vulnrichment

Updated: 2026-09-08T13:58:43.203Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:25.353

Modified: 2026-09-11T20:30:57.210

Link: CVE-2026-73312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay