MEDIUMVulnerability

CVE-2026-73310

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.

Properties

severity
MEDIUM
score
5.9
cve_id
CVE-2026-73310
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-08T14:17:25.073
last_modified
2026-09-11T20:36:03.907

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73310 — Ninja Signal Threat Intelligence | Ninja Signal