Authorization Flaw in XenForo Affects OAuth2 Token Handling
CVE-2026-73310

8.2HIGH

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-73310?

XenForo prior to version 2.3.13 contains a serious authorization flaw within the OAuth2 token endpoint. This vulnerability allows attackers controlling any allowlisted redirect URI to bypass the redirect URI binding. By submitting an alternative allowlisted URI at the time of token exchange, attackers can intercept authorization codes and potentially steal OAuth2 tokens from the affected authorization flows. It is crucial for users to upgrade to the latest version to safeguard their applications against this risk.

Affected Version(s)

XenForo 0 < 2.3.13

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Paciaroni (BomboBombone)
VulnCheck
.