CVE-2026-73309 | XenForo up to 2.3.12 OAuth2 Token Endpoint client_secret/code_verifier improper authorization
A vulnerability, which was classified as critical, was found in XenForo up to 2.3.12. This affects an unknown function of the component OAuth2 Token Endpoint. Executing a manipulation of the argument client_secret/code_verifier can lead to improper authorization.
The identification of this vulnerability is CVE-2026-73309. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More