CVE-2026-73318
Analyzed Analyzed - Analysis Complete

XenForo Missing Authorization in Force-Agreement Controller

Vulnerability report for CVE-2026-73318, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xenforo xenforo to 2.3.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

XenForo before 2.3.13 has a missing authorization flaw in the force-agreement controller. Any ACP administrator can submit force-agreement forms even without required permissions. This bypasses permission checks and updates the global policy timestamp, forcing all users to re-agree to privacy policies or terms of service.

Detection Guidance

Check XenForo version with: grep -r 'XenForo' /path/to/xenforo/install. If version is below 2.3.13, it is vulnerable. Monitor ACP access logs for unauthorized force-agreement submissions or timestamp changes in the database.

Impact Analysis

Attackers with limited ACP access can disrupt user experience by forcing all users to re-accept policies. This may cause confusion, loss of access for users who haven't re-agreed, and potential data processing interruptions if policies govern consent.

Compliance Impact

This vulnerability could disrupt compliance by invalidating existing user consent records. GDPR requires clear consent management, and forced re-agreements may not meet legal standards. HIPAA requires strict access controls; unauthorized policy changes could violate security requirements.

Mitigation Strategies

Upgrade XenForo to version 2.3.13 or later immediately. Review ACP administrator permissions to ensure only authorized users have access to force-agreement controls. Audit recent changes to agreement timestamps in the database.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73318. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart