CVE-2026-73317
PoC ×2largeXenForo ACP missing authorization lets limited admins forge approval-queue actions
XenForo before 2.3.13 contains a missing authorization flaw (CWE-863) in the Admin Control Panel cache-rebuild dispatcher, allowing a restricted administrator to exceed their assigned permissions. An administrator holding only the rebuildCache permission can send a crafted POST request to the cache-rebuild endpoint specifying an arbitrary job class and any actor user ID, causing the approval-queue job to run under an impersonated identity. This lets the attacker approve queued user registrations without holding the required approval-queue or moderator permissions, while the moderation log records the action as performed by the impersonated account. Only XenForo forums running versions prior to 2.3.13 are affected, and exploitation requires someone who already has at least this limited administrative access in the target forum. Exploitation is not currently widespread: the issue is not in CISA KEV, EPSS estimates only a 0.3% chance of exploitation in the next 30 days, and a single public proof-of-concept is available on GitHub.
What to do: Upgrade XenForo to version 2.3.13 or later. As interim mitigation, revoke the rebuildCache permission from limited administrators or restrict it to fully privileged admins until patching is complete. Review the moderation log for approval-queue actions attributed to accounts that lack moderator permissions, which would indicate the flaw was abused.
| XenForo | before 2.3.13 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. Attackers can invoke the approval queue job under any user identity to approve queued user registrations without holding the required approval-queue or moderator permissions, causing the moderation log to attribute actions to an impersonated account.
- Vendors
- xenforo
- Products
- xenforo
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.