Missing Authorization Vulnerability in XenForo's ACP Cache-Rebuild Dispatcher
CVE-2026-73317

5.1MEDIUM

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-73317?

A vulnerability exists in XenForo before version 2.3.13 that affects the ACP cache-rebuild dispatcher. Limited administrators who possess only the rebuildCache permission can exploit this vulnerability to perform unauthorized actions within the approval queue. By providing an arbitrary job class and actor user ID in the POST body, attackers can trigger approval queue jobs under any user identity. This allows them to approve user registrations without having the necessary approval-queue or moderator permissions, leading to unauthorized actions being logged under the impersonated account.

Affected Version(s)

XenForo 0 < 2.3.13

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Paciaroni (BomboBombone)
VulnCheck
.