Description
XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.
Published: 2026-09-08
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

The flaw in the force‑agreement controller allows any ACP administrator to bypass the declared option permission and submit forced agreement forms. This results in the ability to update the global policy timestamp, forcing all users to re‑agree to privacy or terms documents. The vulnerability falls under CWE‑863 and effectively permits an authenticated administrator to perform privileged actions beyond their assigned rights, potentially undermining the platform’s contractual compliance mechanisms.

Affected Systems

XenForo versions prior to 2.3.13 are affected, including 2.3.12 and earlier releases of the XenForo core product. Users running a supported XenForo version of 2.3.13 or higher are not susceptible.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. Exploitability is limited to administrators with ACP access; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread exploitation. Nevertheless, administrators must be aware that any ACP user can hijack the agreement process to force users to re‑accept policies, which may lead to audit or compliance violations.

Generated by OpenCVE AI on September 8, 2026 at 15:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade XenForo to version 2.3.13 or later to apply the vendor‑issued fix.
  • Restrict or remove the force‑agreement controller from administrators who do not require this capability by adjusting ACLs in the Admin Control Panel.
  • Review and audit current Administrator roles to ensure only trusted personnel retain full ACP permissions.
  • Consider disabling the global policy timestamp update feature if not required for your use case.

Generated by OpenCVE AI on September 8, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.
Title XenForo < 2.3.13 Missing Authorization via force-agreement Controller
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T19:33:06.053Z

Reserved: 2026-08-11T19:56:20.007Z

Link: CVE-2026-73318

cve-icon Vulnrichment

Updated: 2026-09-14T19:23:26.332Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:26.197

Modified: 2026-09-14T20:16:50.250

Link: CVE-2026-73318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses