XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
References
| Link | Resource |
|---|---|
| https://bombobombone.github.io/posts/cve-2026-73312/ | Exploit Third Party Advisory |
| https://github.com/BomboBombone/CVE-2026-73312 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/xenforo-refresh-token-replay-via-expired-access-token | Third Party Advisory |
| https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-and-media-gallery-versions-2-2-0-2-3-12.239856/ | Release Notes |
| https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includes-security-fixes.239857/ | Release Notes |
Configurations
History
No history.
Information
Published : 2026-09-08 14:17
Updated : 2026-09-11 20:30
NVD link : CVE-2026-73312
Mitre link : CVE-2026-73312
CVE.ORG link : CVE-2026-73312
JSON object : View
Products Affected
xenforo
- xenforo
CWE
CWE-294
Authentication Bypass by Capture-replay
