CVE-2026-74239
Analyzed Analyzed - Analysis Complete

Path Traversal in XenForo Style Importer

Vulnerability report for CVE-2026-74239, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-11

Assigner: VulnCheck

Description

XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using backslash-based traversal sequences in ZIP member names. Attackers can craft a malicious ZIP archive with backslash path separators that bypass forward-slash validation to write arbitrary bytes to any web-server-writable path, including the public web root, achieving persistent code execution as the web-server account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xenforo xenforo to 2.3.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-74239 is a path traversal vulnerability in XenForo versions before 2.3.13. It affects Windows deployments during style archive imports. The importer fails to block backslash-based path traversal sequences like ..\, allowing authenticated non-super administrators with style permissions to write files outside the intended directory. Attackers can craft malicious ZIP archives with backslash paths to bypass forward-slash validation and place files in web-server-writable locations, including the public web root.

Detection Guidance

Check XenForo version with command: grep -r 'XenForo' /path/to/your/installation | grep 'version'. If version is below 2.3.13, the system is vulnerable. Inspect uploaded style archives for backslash path separators in ZIP members using: unzip -l archive.zip | grep '\\..\\'.

Monitor for unexpected file writes in web root or other writable directories. Look for files like style-archive-sentinel.php created outside intended directories. Review logs for style import attempts from non-super administrators.

Impact Analysis

This vulnerability allows attackers to write arbitrary files to any writable location on the server, including the web root. If successful, they can achieve persistent code execution under the web server's account by placing and executing PHP files. This could lead to full system compromise, data theft, or further lateral movement within the network.

Compliance Impact

This vulnerability could lead to unauthorized file writes and code execution, potentially exposing sensitive data. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A successful exploit may violate these regulations by enabling data breaches or unauthorized access, resulting in legal penalties and reputational damage.

Mitigation Strategies

Upgrade XenForo to version 2.3.13 or later immediately. Remove delegated style permissions from non-super administrators until patched. Disable PHP ZIP support if not required for style imports.

Audit web root and writable directories for suspicious files. Restrict write permissions to web root directories. Monitor for unauthorized file creation or execution attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74239. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart