Impact
The vulnerability is a multi-factor authentication bypass in XenForo’s passkey TFA provider. The verification step performs a global credential lookup without checking that the credential belongs to the account being logged in. An attacker who has already authenticated with a target account’s password can sign the WebAuthn challenge using an attacker‑owned passkey, causing the system to accept the authentication and grant access. This results in the attacker gaining full control of the victim’s account without ever needing the second factor, compromising confidentiality and integrity of user data.
Affected Systems
XenForo Community Forum software, all versions below 2.3.13 – including all bundled add‑ons and media gallery components – are impacted. The flaw appears in both the public forum and Administration Control Panel login flows.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. EPSS data is not available, so the exact exploitation likelihood cannot be quantified. The vulnerability has not been listed in the CISA KEV catalog. An attacker must first authenticate with the victim’s password, after which an attacker‑owned passkey can be used to bypass MFA. The attack requires no special network privileges, making it relatively easy for an insider or external attacker that has compromised credentials.
OpenCVE Enrichment