Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows. | |
| Title | XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T13:46:11.329Z
Reserved: 2026-08-11T19:56:20.007Z
Link: CVE-2026-73310
Updated: 2026-09-08T13:45:57.998Z
Status : Received
Published: 2026-09-08T14:17:25.073
Modified: 2026-09-08T14:17:25.073
Link: CVE-2026-73310
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization