XenForo < 2.3.13 Refresh Token Replay via Expired Access Token
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.1epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
XenForo · XenForopublic PoCs found — 1
cve_referencegithub.com/BomboBombone/CVE-2026-73312★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://bombobombone.github.io/posts/cve-2026-73312/https://github.com/BomboBombone/CVE-2026-73312https://www.vulncheck.com/advisories/xenforo-refresh-token-replay-via-expired-access-tokenhttps://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-and-media-gallery-versions-2-2-0-2-3-12.239856/https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includes-security-fixes.239857/