Missing Authorization Vulnerability in XenForo Affected by Configuration Flaws
CVE-2026-73318
5.1MEDIUM
What is CVE-2026-73318?
A vulnerability exists in XenForo that allows unauthorized access to the force-agreement controller for any ACP administrator. This security flaw enables attackers to bypass permission settings defined in the navigation configuration, allowing them to update the last-updated timestamp of global privacy policies or terms of service. This action forces all users to re-agree to policies without the necessary permissions, undermining user consent and security practices.
Affected Version(s)
XenForo 0 < 2.3.13
