Missing Authorization Vulnerability in XenForo's ACP Cache-Rebuild Dispatcher
CVE-2026-73317
5.1MEDIUM
What is CVE-2026-73317?
A vulnerability exists in XenForo before version 2.3.13 that affects the ACP cache-rebuild dispatcher. Limited administrators who possess only the rebuildCache permission can exploit this vulnerability to perform unauthorized actions within the approval queue. By providing an arbitrary job class and actor user ID in the POST body, attackers can trigger approval queue jobs under any user identity. This allows them to approve user registrations without having the necessary approval-queue or moderator permissions, leading to unauthorized actions being logged under the impersonated account.
Affected Version(s)
XenForo 0 < 2.3.13
