CVE-2026-73317: XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild Dispatcher
XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. Attackers can invoke the approval queue job under any user identity to approve queued user registrations without holding the required approval-queue or moderator permissions, causing the moderation log to attribute actions to an impersonated account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
XenForoto a version that resolves this vulnerability.Fixed in 2.3.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Missing Authorization via ACP Cache-Rebuild Dispatcher
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already have a XenForo administrator account with the rebuildCache permission. No approval-queue or moderator permission is required.
What unauthorized action can be performed?
The attacker can submit an arbitrary job class and actor user ID to invoke the approval queue job, approving queued user registrations under a chosen user identity. The resulting moderation-log entry is attributed to the impersonated account.
Are installations running XenForo 2.3.13 affected?
No. The issue affects XenForo versions before 2.3.13.