<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-73309 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-73309/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 15:41:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-73309/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>XenForo OAuth2 Authorization Code Reuse Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-xenforo-oauth-reuse/</link><pubDate>Tue, 08 Sep 2026 15:41:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-xenforo-oauth-reuse/</guid><description>XenForo versions prior to 2.3.13 contain an OAuth2 authorization code reuse vulnerability (CVE-2026-73311) that allows attackers to obtain unauthorized token pairs by submitting previously used codes.</description><content:encoded><![CDATA[<p>XenForo software versions prior to 2.3.13 contain a critical vulnerability in the handling of OAuth2 authorization codes, tracked as CVE-2026-73311. The application fails to properly invalidate or mark authorization codes as consumed after the initial token issuance. This oversight allows an attacker to replay a previously used authorization code to the token endpoint, bypassing the mandatory single-use security guarantee required by the OAuth2 specification. By successfully re-submitting the code, the attacker can receive an independent, unauthorized token pair for the same user and associated scopes. This vulnerability represents a significant risk to user account integrity and session security, as it facilitates unauthorized access to account data and privileges without requiring further interaction from the target user. Defenders should prioritize updating to version 2.3.13 or later to ensure compliance with OAuth2 security standards.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to gain unauthorized access to user accounts, potentially leading to full account takeover or unauthorized data exfiltration depending on the scopes associated with the leaked token. The vulnerability affects any XenForo environment utilizing the OAuth2 authorization code flow.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all XenForo instances to version 2.3.13 or later immediately to address the underlying authorization code validation logic (CVE-2026-73311).</li>
<li>Review OAuth2 token usage logs to identify instances of duplicate authorization code submission.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>vulnerability</category><category>authentication-bypass</category><category>cve-2026-73309</category><category>web-application-vulnerability</category></item></channel></rss>