XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
References
| Link | Resource |
|---|---|
| https://www.vulncheck.com/advisories/xenforo-remote-code-execution-via-authenticated-admin | Third Party Advisory |
| https://xenforo.com/community/threads/xenforo-2-3-9-inc-xfmg-2-2-18-released-security-fix.235659/ | Release Notes |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-01 01:16
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35056
Mitre link : CVE-2026-35056
CVE.ORG link : CVE-2026-35056
JSON object : View
Products Affected
xenforo
- xenforo
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
