CVE-2026-73312: Three OAuth2 vulnerabilities in XenForo
This text was generated using artificial intelligence (AI).XenForo released security fixes for three OAuth2 vulnerabilities in XenForo on September 8, 2026. Affected are XenForo versions prior to 2.3.13. The CVEs CVE-2026-73309, CVE-2026-73311 and CVE-2026-73312 are each with CVSS 4.0: 9.1 rated.
According to XenForo, version 2.3.13 Security fixes for the affected versions. Organizations should therefore catalog publicly accessible XenForo instances, check their patch status, and prioritize updating systems prior to 2.3.13.
The three vulnerabilities affect different checks and single-use rules in the OAuth2 flow.
CVE-2026-73312: Refresh Token Reuse
According to the XenForo advisory, it enables CVE-2026-73312 the multiple use of a refresh token when the associated access token has expired. In this case, the refresh token is not marked as consumed. As a result, additional independent token pairs can be generated. Unauthorized access can persist for the lifetime of the token.
CVE-2026-73311: Authorization Code Reuse
According to the XenForo vendor advisory, it affects CVE-2026-73311 the reuse of already used OAuth2 authorization codes. An authorization code is not invalidated or marked as consumed after the first token issuance. As a result, additional token pairs can be issued for the same identity and the same permissions.
CVE-2026-73309: Bypass at the OAuth2 token endpoint
The XenForo advisory describes at CVE-2026-73309 a bypass of the authentication check at the OAuth2 token endpoint. Empty values for client_secret and code_verifier can bypass checks because empty strings are treated as false in PHP evaluation. As a result, a valid authorization code can be exchanged for a token pair without proving the client identity or the PKCE binding.
Apply patches and check access logs
The patch to XenForo 2.3.13 or higher is the documented workaround. For systems that were publicly accessible prior to the update, post-remediation also includes checking active OAuth2 token pairs and sessions for unauthorized access.
In this regard, the following observations are particularly relevant:
repeatedly issued token pairs,
Sessions that cannot be assigned to an expected registration,
Accesses that indicate unauthorized use of OAuth2 tokens.
For operators of publicly accessible XenForo instances in Germany and Austria: If OAuth2 token pairs are misused by unauthorized third parties and personal user data is accessed, a reporting obligation under Article 33 GDPR may be triggered within 72 hours. Organizations subject to NIS-2 in Germany and Austria should document whether they are affected as part of their vulnerability management. For Switzerland, the revised Information Security Act (ISA) applies, with a reporting obligation to BACS.
In addition to updates, continuous vulnerability and supplier monitoring helps recheck affected systems after security advisories and process them with priority.
LocateRisk EASM can identify XenForo instances under customer domains and discover publicly accessible web applications for patch auditing. This creates a working basis to locate XenForo systems prior to version 2.3.13 in the inventory and prioritize their remediation.
The platform makes publicly accessible systems and deployed software visible. However, it does not necessarily detect the specific vulnerable version and does not replace updates or the checking of OAuth2 token pairs, sessions, or authentication flows.
C-VRM complements this view of one's own infrastructure in the supplier context: critical vulnerabilities at vendors or a declining security level of vendors can be tracked. For XenForo, the technical measure remains clear: check vulnerability status and patch status, update to the bug-fixed version, and investigate suspicious token pairs and sessions.
Am I affected?
XenForo in the aforementioned versions is affected; the vulnerability was fixed in 2.3.13. Anyone who wants to know if XenForo is even visible in their own externally accessible infrastructure can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
The three vulnerabilities affect different checks in the OAuth2 flow: CVE-2026-73312 allows the multiple use of a refresh token after the expiration of the associated access token. CVE-2026-73311 enables the reuse of already used authorization codes. CVE-2026-73309 allows the authentication check at the token endpoint to be bypassed through empty parameter values.
All XenForo versions prior to 2.3.13 are affected. The documented workaround is to update to XenForo 2.3.13 or higher. XenForo released the fix on September 8, 2026.
Following the update, active OAuth2 token pairs and sessions should be examined for anomalies — in particular, repeatedly issued token pairs and sessions that cannot be associated with an expected login. Systems that were publicly accessible prior to the update must be given special consideration in this regard.
As of September 8, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-73312
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.