← back
CVE-2026-73317mediumCWE-863

XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild Dispatcher

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 5.1epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. Attackers can invoke the approval queue job under any user identity to approve queued user registrations without holding the required approval-queue or moderator permissions, causing the moderation log to attribute actions to an impersonated account.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
XenForo · XenForo
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.