Remote Code Execution Vulnerability in XenForo Software by XenForo Ltd.
CVE-2026-35056

8.6HIGH

Key Information:

Vendor
CVE Published:
1 April 2026

What is CVE-2026-35056?

XenForo versions prior to 2.3.9 and 2.2.18 are susceptible to a remote code execution vulnerability that could allow authenticated admin users to execute arbitrary code on the server. This vulnerability arises from insufficient validation of user permissions within the admin panel, providing opportunities for malicious insiders to exploit their access. It's imperative for administrators to upgrade to the latest versions to safeguard against potential breaches.

Affected Version(s)

XenForo 2.3.0 < 2.3.9

XenForo 0 < 2.2.18

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

UwU
.