CVE-2026-73320
Analyzed Analyzed - Analysis Complete

XenForo Unauthenticated Information Disclosure via Predictable IDs

Vulnerability report for CVE-2026-73320, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-11

Assigner: VulnCheck

Description

XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoint. Attackers can enumerate or predict result IDs and query the endpoint without any session, user, or visibility checks to obtain rendered preview HTML, original URLs, and query strings from private conversations and other restricted content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xenforo xenforo to 2.3.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-73320 is an unauthenticated information disclosure vulnerability in XenForo versions before 2.3.13. It affects the unfurl.php endpoint, which allows attackers to retrieve private link preview records by guessing sequential numeric IDs without authentication. The endpoint returns rendered preview HTML and original URLs from restricted content, including private conversations.

Detection Guidance

To detect this vulnerability, monitor access logs for unusual requests to the unfurl.php endpoint with sequential numeric IDs. Check for POST requests containing UnfurlResult IDs without valid sessions. Use tools like grep to search logs for patterns like 'unfurl.php' and numeric parameters.

Impact Analysis

Attackers could access sensitive data like preview HTML, original URLs, and query strings from private conversations or restricted content. This may expose confidential information, user interactions, or internal links. The attack requires predicting IDs but is feasible with timing precision and a public proof-of-concept available.

Compliance Impact

This vulnerability could lead to unauthorized access to private user data, violating GDPR's data protection principles and HIPAA's confidentiality requirements. Organizations using affected XenForo versions may face compliance breaches, legal liabilities, and reputational damage due to exposed sensitive information.

Mitigation Strategies

Immediately upgrade XenForo to version 2.3.13 or later to patch the vulnerability. If upgrading is not possible, restrict access to the unfurl.php endpoint via web server rules or firewall to block unauthenticated requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73320. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart