Executive brief
XenForo is a popular forum and community platform that uses OAuth2 tokens for user authentication. A vulnerability in versions before 2.3.13 allows attackers who possess a user's refresh token to repeatedly reuse it after the associated access token expires, generating multiple valid token pairs and maintaining unauthorized access for an extended period. This could allow account takeover or data access if a refresh token is compromised.
Technical details
The vulnerability is a refresh token replay flaw in XenForo's OAuth2 token refresh endpoint. When a refresh token is submitted after its parent access token has expired, the refresh endpoint creates a new token pair but then attempts to revoke the old access token. However, the revocation routine checks whether the old access token is still valid and returns early if it's expired, bypassing the revocation of the associated refresh token. This allows the original refresh token to be reused multiple times to generate independent token families. An attacker must already possess a valid refresh token (and the client secret for confidential clients); this is not a login bypass. XenForo 2.3.13 fixes this by consuming the refresh token independently of the parent access token's validity state.
Affected products
- XenForo XenForo before 2.3.13
Timeline
- 2026-09-08: disclosed: CVE-2026-73312 published
- 2026-09-08: patched: XenForo 2.3.13 released with fix