Authorization Flaw in XenForo Affects OAuth2 Token Handling
CVE-2026-73310
8.2HIGH
What is CVE-2026-73310?
XenForo prior to version 2.3.13 contains a serious authorization flaw within the OAuth2 token endpoint. This vulnerability allows attackers controlling any allowlisted redirect URI to bypass the redirect URI binding. By submitting an alternative allowlisted URI at the time of token exchange, attackers can intercept authorization codes and potentially steal OAuth2 tokens from the affected authorization flows. It is crucial for users to upgrade to the latest version to safeguard their applications against this risk.
Affected Version(s)
XenForo 0 < 2.3.13
