Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-73309

CVE-2026-73309: XenForo OAuth2 Authentication Bypass Flaw

CVE-2026-73309 is an authentication bypass flaw in XenForo before 2.3.13 that exploits OAuth2 token endpoint weaknesses. Attackers can obtain valid tokens without proper authentication. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-73309 Overview

CVE-2026-73309 is an authentication bypass vulnerability in XenForo versions before 2.3.13. The flaw resides in the OAuth2 token endpoint and stems from unsafe PHP truthy evaluation of the client_secret and code_verifier parameters. Unauthenticated attackers who obtain a valid authorization code can exchange it for a token pair by submitting empty values for both parameters, bypassing client authentication and Proof Key for Code Exchange (PKCE) validation. The issue is classified under [CWE-697] (Incorrect Comparison).

Critical Impact

Remote unauthenticated attackers can mint valid OAuth2 access tokens on affected XenForo installations, compromising the confidentiality and integrity of protected forum resources.

Affected Products

  • XenForo versions 2.2.0 through 2.3.12
  • XenForo Media Gallery add-on (versions matching the above releases)
  • Any XenForo deployment exposing the OAuth2 token endpoint

Discovery Timeline

  • 2026-09-08 - CVE-2026-73309 published to the National Vulnerability Database (NVD)
  • 2026-09-09 - Last updated in NVD database

Technical Details for CVE-2026-73309

Vulnerability Analysis

The vulnerability targets the OAuth2 token endpoint in XenForo, which issues access and refresh tokens in exchange for an authorization code. During the exchange, the server must verify two things: the requesting client's identity through a client_secret (for confidential clients) and the PKCE binding through a code_verifier that matches the previously stored code_challenge.

Instead of performing an explicit presence check, XenForo evaluates these parameters using PHP truthy semantics. An empty string evaluates to false, so the server treats a missing verifier as though no verification was requested and skips the validation branch entirely. An attacker who intercepts or obtains a valid authorization code can therefore complete the token exchange without proving client identity or knowing the PKCE secret.

Root Cause

The root cause is an incorrect comparison ([CWE-697]) between user-supplied input and expected credentials. Validation logic uses conditional checks that short-circuit when parameters are falsy, rather than requiring the parameters to be present and matching the stored values. This design collapses two distinct security controls, client authentication and PKCE, into optional code paths.

Attack Vector

An attacker first obtains a valid authorization code, which can occur through open redirector abuse, referer leakage, or interception of a legitimate flow. The attacker then issues an HTTP POST to the token endpoint containing the code and empty strings for client_secret and code_verifier. XenForo returns a valid access and refresh token pair bound to the victim account, granting API access equivalent to the legitimate client. Refer to the VulnCheck Advisory for XenForo Bypass and the BomboBombone CVE-2026-73309 Overview for the full exploitation walkthrough.

Detection Methods for CVE-2026-73309

Indicators of Compromise

  • POST requests to the XenForo OAuth2 token endpoint where the client_secret or code_verifier form fields are present but empty.
  • Successful token issuance immediately following an authorization code request from a different source IP or user agent.
  • Unexpected use of OAuth access tokens from IPs that never completed a browser-based authorization flow.

Detection Strategies

  • Inspect web server and application logs for grant_type=authorization_code requests missing non-empty client_secret and code_verifier values.
  • Correlate authorization code issuance with subsequent token exchanges to identify mismatched client fingerprints.
  • Alert on API activity performed by tokens issued to confidential clients that did not present a secret.

Monitoring Recommendations

  • Enable verbose OAuth2 logging on XenForo and forward events to a SIEM for retention and correlation.
  • Baseline expected client identifiers and PKCE usage patterns, then alert on deviations.
  • Monitor for anomalous account activity, such as profile changes or private message access, following recent authorization events.

How to Mitigate CVE-2026-73309

Immediate Actions Required

  • Upgrade all XenForo installations to version 2.3.13 or later, and update XenForo Media Gallery in parallel.
  • Rotate any OAuth2 client secrets and revoke outstanding access and refresh tokens issued before patching.
  • Review OAuth2 client registrations and remove any that are unused or unrecognized.

Patch Information

XenForo has released fixed builds and back-ported patches for supported branches. See the XenForo Security Fixes Announcement and the XenForo 2.3.13 Release with Fixes for supported upgrade paths and applicable hotfixes.

Workarounds

  • Restrict access to the OAuth2 token endpoint at the web server or WAF layer, blocking requests that contain empty client_secret or code_verifier values.
  • Temporarily disable OAuth2 integrations on affected XenForo instances until patching is complete.
  • Enforce short authorization code lifetimes to reduce the window in which an intercepted code can be exchanged.
bash
# Example NGINX rule to block token requests with empty client_secret or code_verifier
location = /api/oauth2/token {
    if ($request_method = POST) {
        if ($request_body ~* "client_secret=(&|$)") { return 400; }
        if ($request_body ~* "code_verifier=(&|$)") { return 400; }
    }
    proxy_pass http://xenforo_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.