CVE-2026-73310: XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass

Published Sep 8, 2026
·
Updated

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.

Affected Software

1 affected component
XenForo Xenforo<2.3.13

Event History

Sep 8, 2026
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

XenForo versions before 2.3.13 are affected where OAuth2 authorization-code flows use allowlisted redirect URIs. An attacker must control one of those allowlisted redirect URIs.

2

What does an attacker need to exploit the flaw?

The attacker needs an intercepted OAuth2 authorization code and control of any allowlisted redirect URI. They can submit a different allowlisted redirect URI when exchanging the code, rather than the URI recorded during authorization.

3

What is the impact if exploitation succeeds?

A successful attacker can exchange an intercepted authorization code and obtain OAuth2 tokens from the intercepted authorization flow. The provided data identifies confidentiality impact only; it does not indicate integrity or availability impact.

4

What version remediates the issue?

Upgrade XenForo to version 2.3.13 or later. The affected range is XenForo versions before 2.3.13.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203