SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73313

MEDIUM · CVSS 6.8 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

XenForo versions prior to 2.3.13 are vulnerable to a multi-factor authentication bypass that allows authenticated attackers to log in as other users by exploiting the passkey TFA provider. This vulnerability occurs during the WebAuthn assertion step, where the system fails to validate that the matched credential belongs to the intended user, enabling attackers with knowledge of a target account's password to bypass MFA protections. Organizations using affected XenForo versions should prioritize patching to mitigate the risk of unauthorized account access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73313
Severity
MEDIUM
CVSS
6.8
EPSS
0.39%

Original NVD Description

XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.

Related CVEs

Other vulnerabilities affecting the same vendor(s)