CVE-2026-73311: XenForo < 2.3.13 OAuth2 Authorization Code Reuse

Published Sep 8, 2026
·
Updated

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token issuance to receive an independent token pair for the same user and scopes, bypassing the single-use guarantee of the OAuth2 authorization code flow.

Affected Software

1 affected component
XenForo Xenforo<2.3.13

Event History

Sep 8, 2026
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

XenForo versions before 2.3.13 are affected. The issue applies to OAuth2 authorization-code handling where an authorization code can be submitted again after token issuance.

2

What does an attacker need to exploit this issue?

An attacker needs a previously used OAuth2 authorization code. No privileges or user interaction are required according to the supplied severity vector, but exploitation has high attack complexity.

3

What is the impact of successfully reusing an authorization code?

A successful attacker can obtain an independent OAuth2 token pair for the same user and scopes associated with the reused code. This can result in high confidentiality and integrity impact, without an indicated availability impact.

4

How can I determine whether my instance is vulnerable?

Check the XenForo version in use. Instances running a version earlier than 2.3.13 should be considered affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203