CVE-2026-73309

XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which treats empty strings as false and skips client secret validation and PKCE code verifier validation, to exchange a valid authorization code for a token pair without proving client identity or holding the PKCE commitment.

  • Published Sep 8, 2026
  • CVSS 9.1 critical
  • 0.7% chance of exploitation in the next 30 days (EPSS)
  • Public exploit code is available
  • A fix is available

Affected software

CVE-2026-73309 at the National Vulnerability Database