SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73310

MEDIUM · CVSS 5.9 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

XenForo versions prior to 2.3.13 are vulnerable due to an authorization flaw in the OAuth2 token endpoint, allowing attackers to exploit allowlisted redirect URIs to bypass redirect URI binding. This vulnerability enables the interception of authorization codes, potentially leading to the theft of OAuth2 tokens. Organizations using affected versions of XenForo should prioritize patching to mitigate the risk of unauthorized access to sensitive user data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73310
Severity
MEDIUM
CVSS
5.9
EPSS
0.36%
Exchange

Original NVD Description

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.

Related CVEs

Other vulnerabilities affecting the same vendor(s)