Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 09 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 08 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Vendors & Products |
Xenforo
Xenforo xenforo |
Tue, 08 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment. | |
| Title | XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint | |
| Weaknesses | CWE-697 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-09T16:01:46.890Z
Reserved: 2026-08-11T19:56:20.006Z
Link: CVE-2026-73309
Updated: 2026-09-09T16:01:39.863Z
Status : Awaiting Analysis
Published: 2026-09-08T14:17:24.913
Modified: 2026-09-09T17:17:38.100
Link: CVE-2026-73309
No data.
OpenCVE Enrichment
Updated: 2026-09-08T15:15:17Z