Description
XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.
Published: 2026-09-08
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a multi-factor authentication bypass in XenForo’s passkey TFA provider. The verification step performs a global credential lookup without checking that the credential belongs to the account being logged in. An attacker who has already authenticated with a target account’s password can sign the WebAuthn challenge using an attacker‑owned passkey, causing the system to accept the authentication and grant access. This results in the attacker gaining full control of the victim’s account without ever needing the second factor, compromising confidentiality and integrity of user data.

Affected Systems

XenForo Community Forum software, all versions below 2.3.13 – including all bundled add‑ons and media gallery components – are impacted. The flaw appears in both the public forum and Administration Control Panel login flows.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity. EPSS data is not available, so the exact exploitation likelihood cannot be quantified. The vulnerability has not been listed in the CISA KEV catalog. An attacker must first authenticate with the victim’s password, after which an attacker‑owned passkey can be used to bypass MFA. The attack requires no special network privileges, making it relatively easy for an insider or external attacker that has compromised credentials.

Generated by OpenCVE AI on September 8, 2026 at 15:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official XenForo patch to version 2.3.13 or later.
  • If a patch cannot be applied immediately, disable the passkey TFA provider or temporarily suspend MFA for all users until the update is available.
  • Review logs for anomalous login activity and reset passwords for any accounts that may have been compromised during the vulnerability window.

Generated by OpenCVE AI on September 8, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.
Title XenForo < 2.3.13 MFA Bypass via Passkey TFA Provider
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-08T13:17:30.351Z

Reserved: 2026-08-11T19:56:20.007Z

Link: CVE-2026-73313

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T14:17:25.500

Modified: 2026-09-08T14:17:25.500

Link: CVE-2026-73313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses