HIGHVulnerability

CVE-2026-73314

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing the caller to treat the fabricated request as verified and process the payment event without a valid PayPal signature.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-73314
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
published_at
2026-09-08T14:17:25.640
last_modified
2026-09-11T20:31:16.703

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Improper Check for Unusual or Exceptional Conditions

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73314 — Ninja Signal Threat Intelligence | Ninja Signal