Multi-Factor Authentication Bypass in XenForo WebAuthn TFA Provider
CVE-2026-73313
7.6HIGH
What is CVE-2026-73313?
A vulnerability in XenForo prior to version 2.3.13 allows an authenticated attacker to bypass multi-factor authentication through the passkey TFA provider. The security flaw occurs during the WebAuthn assertion step, where the passkey verification fails to ensure that the matched credential belongs to the intended user. This oversight permits an attacker, who possesses the target account's password, to submit their own registered passkey, thereby gaining unauthorized access to both public forum and ACP login paths.
Affected Version(s)
XenForo 0 < 2.3.13
