Executive brief
XenForo is a popular community forum platform. A vulnerability in the administrative control panel allows restricted administrators to bypass permission checks and force all users on a forum to re-accept privacy policies and terms of service, causing a site-wide disruption until each user complies.
Technical details
The vulnerability is a missing authorization check in the ForceAgreementController. The ACP navigation interface correctly hides force-agreement controls from administrators lacking the "option" permission, but the controller itself does not enforce this permission check. An authenticated ACP administrator without the required permission can send direct POST requests to privacy-policy and terms reset endpoints, which return HTTP 200 and update global agreement timestamps. When timestamps advance, all existing user acceptances become invalid, forcing every user through the re-agreement flow. The fix, applied in XenForo 2.3.13, adds controller-level permission enforcement.
Affected products
- XenForo XenForo before 2.3.13
Timeline
- 2026-09-08: disclosed: CVE-2026-73318 published
- 2026-09: patched: Fix included in XenForo 2.3.13