CVE-2026-73317
Awaiting Analysis Awaiting Analysis - Queue

XenForo Missing Authorization in ACP Cache-Rebuild Dispatcher

Vulnerability report for CVE-2026-73317, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. Attackers can invoke the approval queue job under any user identity to approve queued user registrations without holding the required approval-queue or moderator permissions, causing the moderation log to attribute actions to an impersonated account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-09
AI Q&A
2026-09-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xenforo xenforo to 2.3.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

XenForo before version 2.3.13 has a missing authorization vulnerability in the ACP cache-rebuild dispatcher. Limited administrators with only the rebuildCache permission can perform unauthorized approval queue actions by sending an arbitrary job class and actor user ID in the POST request body. This allows attackers to invoke approval queue jobs under any user identity, enabling them to approve queued user registrations without proper approval-queue or moderator permissions. The moderation log then attributes these actions to the impersonated account.

Impact Analysis

This vulnerability allows unauthorized users with limited admin privileges to approve user registrations without proper permissions. It can lead to unauthorized account approvals, bypassing moderation controls, and misleading attribution of actions in the moderation log. The impact includes potential security risks from unauthorized access and compromised moderation integrity.

Mitigation Strategies

Upgrade XenForo to version 2.3.13 or later to address the missing authorization vulnerability in the ACP cache-rebuild dispatcher.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73317. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart