HIGHVulnerability

CVE-2026-73315

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata services, potentially disclosing IAM credentials or enabling secondary internal service exploitation.

Properties

severity
HIGH
score
8.6
cve_id
CVE-2026-73315
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
published_at
2026-09-08T14:17:25.780
last_modified
2026-09-11T20:31:26.440

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73315 — Ninja Signal Threat Intelligence | Ninja Signal