SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73318

LOW · CVSS 3.8 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

XenForo versions prior to 2.3.13 are vulnerable due to a missing authorization flaw in the force-agreement controller, enabling any ACP administrator to access and submit force-agreement forms without proper permissions. This vulnerability allows unauthorized updates to the global policy timestamp, potentially forcing all users to re-accept privacy policies or terms of service. Organizations using XenForo should prioritize this issue to mitigate the risk of unauthorized policy enforcement and ensure compliance.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73318
Severity
LOW
CVSS
3.8
EPSS
0.32%

Original NVD Description

XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)