{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-73309/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-73311"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["XenForo (\u003c 2.3.13)"],"_cs_severities":["high"],"_cs_tags":["web-application","vulnerability","authentication-bypass","cve-2026-73309","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["XenForo"],"content_html":"\u003cp\u003eXenForo software versions prior to 2.3.13 contain a critical vulnerability in the handling of OAuth2 authorization codes, tracked as CVE-2026-73311. The application fails to properly invalidate or mark authorization codes as consumed after the initial token issuance. This oversight allows an attacker to replay a previously used authorization code to the token endpoint, bypassing the mandatory single-use security guarantee required by the OAuth2 specification. By successfully re-submitting the code, the attacker can receive an independent, unauthorized token pair for the same user and associated scopes. This vulnerability represents a significant risk to user account integrity and session security, as it facilitates unauthorized access to account data and privileges without requiring further interaction from the target user. Defenders should prioritize updating to version 2.3.13 or later to ensure compliance with OAuth2 security standards.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to gain unauthorized access to user accounts, potentially leading to full account takeover or unauthorized data exfiltration depending on the scopes associated with the leaked token. The vulnerability affects any XenForo environment utilizing the OAuth2 authorization code flow.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all XenForo instances to version 2.3.13 or later immediately to address the underlying authorization code validation logic (CVE-2026-73311).\u003c/li\u003e\n\u003cli\u003eReview OAuth2 token usage logs to identify instances of duplicate authorization code submission.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T19:46:08Z","date_published":"2026-09-08T15:41:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-xenforo-oauth-reuse/","summary":"XenForo versions prior to 2.3.13 contain an OAuth2 authorization code reuse vulnerability (CVE-2026-73311) that allows attackers to obtain unauthorized token pairs by submitting previously used codes.","title":"XenForo OAuth2 Authorization Code Reuse Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-xenforo-oauth-reuse/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-73309","version":"https://jsonfeed.org/version/1.1"}