Multi-Factor Authentication Bypass in XenForo WebAuthn TFA Provider
CVE-2026-73313

7.6HIGH

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-73313?

A vulnerability in XenForo prior to version 2.3.13 allows an authenticated attacker to bypass multi-factor authentication through the passkey TFA provider. The security flaw occurs during the WebAuthn assertion step, where the passkey verification fails to ensure that the matched credential belongs to the intended user. This oversight permits an attacker, who possesses the target account's password, to submit their own registered passkey, thereby gaining unauthorized access to both public forum and ACP login paths.

Affected Version(s)

XenForo 0 < 2.3.13

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Paciaroni (BomboBombone)
VulnCheck
.