CVE-2026-73309

Summary

XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.

Affected Software

VendorProductVersion RangeStatus
XenForoXenForo0 < 2.3.13affected

Weaknesses

  • CWE-697: Incorrect Comparison

References