SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73312

HIGH · CVSS 7.4 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

XenForo versions prior to 2.3.13 are vulnerable to a refresh token replay attack, where attackers can exploit the system's failure to invalidate refresh tokens after the corresponding access token expires. This allows for the unauthorized generation of new token pairs, enabling persistent access to the system. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73312
Severity
HIGH
CVSS
7.4
EPSS
0.35%

Original NVD Description

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.

Related CVEs

Other vulnerabilities affecting the same vendor(s)