Executive brief
XenForo is a popular community forum platform that includes OAuth2 authentication for third-party applications. A vulnerability in the OAuth2 token endpoint allows attackers who obtain a valid authorization code to bypass PKCE (Proof Key for Code Exchange) verification and client secret validation by submitting empty strings. This enables attackers to obtain forged access tokens without proving their identity, potentially allowing them to impersonate legitimate users and access their authorized data.
Technical details
The vulnerability is an authentication bypass in XenForo's OAuth2 token endpoint caused by improper input validation. The token endpoint checks whether client_secret and code_verifier parameters exist but fails to validate they are non-empty before performing cryptographic verification. PHP's truthy evaluation treats empty strings as false, causing the verification logic guarded by if ($input['client_secret']) and if ($input['code_verifier']) conditionals to be skipped entirely. An attacker with a valid authorization code can exchange it for a token pair without providing the PKCE verifier or client secret. The vulnerability affects both the authorization-code and refresh-token grant types. XenForo 2.3.13 fixes the issue by rejecting empty credentials before processing grants.
Affected products
- XenForo XenForo before 2.3.13
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fixed in XenForo 2.3.13