CVE-2026-73311

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token issuance to receive an independent token pair for the same user and scopes, bypassing the single-use guarantee of the OAuth2 authorization code flow.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-08 14:17

Updated : 2026-09-11 20:30


NVD link : CVE-2026-73311

Mitre link : CVE-2026-73311

CVE.ORG link : CVE-2026-73311


JSON object : View

Products Affected

xenforo

  • xenforo
CWE
CWE-294

Authentication Bypass by Capture-replay