chiprook
← Security
SecuritySeptember 26, 2026, 09:20

XenForo 2.3.13 fixes two authentication flaws

XenForo 2.3.13 patched two authentication bugs: empty client_secret and code_verifier bypassing OAuth2 checks (CVE-2026-73309, CVSS up to 9.1) and a passkey two-step verification flaw that accepted a credential owned by another account (CVE-2026-73313).

XenForo 2.3.13 fixes two authentication flaws
#XenForo
Read next
Security

SharePoint Flaw Reclassified: Spoofing Bug Enables Authenticated RCE

Security

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

Security

Vicarius launches ScriptAI to write fixes for flaws with no vendor patch

Security

Exim 4.100.1 fixes four flaws, including Proxy Protocol and SMTP smuggling