SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73317

LOW · CVSS 2.7 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

XenForo versions prior to 2.3.13 are vulnerable due to a missing authorization flaw in the ACP cache-rebuild dispatcher, allowing limited administrators to execute unauthorized approval queue actions. This can lead to the approval of user registrations without proper permissions, enabling impersonation and potentially compromising the integrity of the moderation log. Organizations using affected versions should prioritize patching to mitigate risks associated with unauthorized user actions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73317
Severity
LOW
CVSS
2.7
EPSS
0.27%

Original NVD Description

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. Attackers can invoke the approval queue job under any user identity to approve queued user registrations without holding the required approval-queue or moderator permissions, causing the moderation log to attribute actions to an impersonated account.

Related CVEs

Other vulnerabilities affecting the same vendor(s)