CVE-2026-73310: XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass
XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
XenForo versions before 2.3.13 are affected where OAuth2 authorization-code flows use allowlisted redirect URIs. An attacker must control one of those allowlisted redirect URIs.
What does an attacker need to exploit the flaw?
The attacker needs an intercepted OAuth2 authorization code and control of any allowlisted redirect URI. They can submit a different allowlisted redirect URI when exchanging the code, rather than the URI recorded during authorization.
What is the impact if exploitation succeeds?
A successful attacker can exchange an intercepted authorization code and obtain OAuth2 tokens from the intercepted authorization flow. The provided data identifies confidentiality impact only; it does not indicate integrity or availability impact.
What version remediates the issue?
Upgrade XenForo to version 2.3.13 or later. The affected range is XenForo versions before 2.3.13.