Description
XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using backslash-based traversal sequences in ZIP member names. Attackers can craft a malicious ZIP archive with backslash path separators that bypass forward-slash validation to write arbitrary bytes to any web-server-writable path, including the public web root, achieving persistent code execution as the web-server account.
Published: 2026-09-08
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Persistent code execution via web‑server account
Action: Immediate Patch
AI Analysis

Impact

The weakness is a path traversal flaw in XenForo’s style archive importer on Windows. By uploading a ZIP file that contains filenames with backslash separators, an authenticated user who has style‑edit permissions but is not a super administrator can cause the importer to extract files outside the expected directory. The backslashes bypass the forward‑slash check, allowing arbitrary file creation or overwrite wherever the web server can write. If the attacker places executable code in the public web root or another writable location, the web server will run it under its own account, granting the attacker persistent control over the application.

Affected Systems

Any XenForo installation running a Windows operating system and having a version earlier than 2.3.13 is vulnerable. The issue is tied to the native style‑archive import feature, independent of add‑ons, and does not affect Linux or macOS deployments.

Risk and Exploitability

With a CVSS score of 8.6 the vulnerability is considered high severity, indicating a serious threat to confidentiality, integrity, and availability. No EPSS score is available, but the requirement of user authentication with style‑permissions means that an attacker must first compromise or obtain credentials for a regular user. Once authenticated, the attacker can craft the malicious ZIP archive and trigger the importer; no special network exposure is needed beyond normal web service access. The vulnerability is not listed in the CISA KEV catalog and no official exploits are publicly documented, yet the path traversal itself directly enables arbitrary file writes that lead to code execution.

Generated by OpenCVE AI on September 8, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade XenForo to version 2.3.13 or later, which removes the faulty path validation.
  • If upgrade is not immediately possible, revoke style‑import permissions from all non‑super‑administrator accounts or disable the style‑archive importer feature entirely.
  • Limit the web‑server account’s write permissions so that it cannot modify directories such as the public web root, reducing the impact of any remaining traversal vectors.

Generated by OpenCVE AI on September 8, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using backslash-based traversal sequences in ZIP member names. Attackers can craft a malicious ZIP archive with backslash path separators that bypass forward-slash validation to write arbitrary bytes to any web-server-writable path, including the public web root, achieving persistent code execution as the web-server account.
Title XenForo < 2.3.13 Path Traversal via Style Archive Importer on Windows
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T01:13:23.729Z

Reserved: 2026-08-14T18:01:19.917Z

Link: CVE-2026-74239

cve-icon Vulnrichment

Updated: 2026-09-08T14:00:56.785Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:26.750

Modified: 2026-09-11T20:30:32.290

Link: CVE-2026-74239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')