Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73313— XenForo < 2.3.13 MFA Bypass via Passkey TFA Provider

Quick assessment

Affected
XenForo XenForo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

XenForo 2.3.13 之前的版本中,passkey(通行密钥)双因素认证(TFA)提供商存在多因素认证绕过漏洞。该漏洞允许已认证的攻击者在 WebAuthn 断言(assertion)阶段提交自己已注册的 passkey 凭据,从而以其他用户的身份完成登录。由于 passkey 验证路径执行的是全局凭据查找,且未验证匹配的凭据是否属于当前待登录的用户,因此,知道目标账户密码的攻击者可以使用自己的 passkey 对挑战值进行签名,从而在公开论坛登录和管理后台(ACP)登录路径上绕过多因素认证。

CVSS 6.8 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
XenForo XenForo < 2.3.13 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73313

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
XenForo < 2.3.13 MFA Bypass via Passkey TFA Provider
Source: CVE Program / CVE List V5
Vulnerability Description
XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
XenForo XenForo 0 ~ 2.3.13 -

II. Public POCs for CVE-2026-73313

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73313

登录查看更多情报信息。

Vendor Advisories for CVE-2026-73313 (1)

Exploits & Public PoCs for CVE-2026-73313 (1)

Security Blog Posts for CVE-2026-73313 (1)

Same Patch Batch · XenForo · 2026-09-08 · 14 CVEs total

CVE-2026-73315 8.6 HIGH XenForo < 2.3.13 SSRF via PayPal REST Webhook Handler
CVE-2026-73314 7.5 HIGH XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook
CVE-2026-73316 7.5 HIGH XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider
CVE-2026-73311 7.4 HIGH XenForo < 2.3.13 OAuth2 Authorization Code Reuse
CVE-2026-73309 7.4 HIGH XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
CVE-2026-73312 7.4 HIGH XenForo < 2.3.13 Refresh Token Replay via Expired Access Token
CVE-2026-74239 7.2 HIGH XenForo < 2.3.13 Path Traversal via Style Archive Importer on Windows
CVE-2026-73321 6.5 MEDIUM XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser
CVE-2026-73320 6.1 MEDIUM XenForo < 2.3.13 Unauthenticated Information Disclosure via Unfurl Endpoint
CVE-2026-73319 6.1 MEDIUM XenForo < 2.3.13 XSS via Dynamic Redirect Handler
CVE-2026-73310 5.9 MEDIUM XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass
CVE-2026-73318 3.8 LOW XenForo < 2.3.13 Missing Authorization via force-agreement Controller
CVE-2026-73317 2.7 LOW XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild Dispatcher

IV. Related Vulnerabilities

V. Comments for CVE-2026-73313

No comments yet


Leave a comment