Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-73309 — Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty client-secret and PKCE verification bypass with a Python script. | Kitploit
أدوات/GitHubGitHub/bombobombone/cve-2026-73309
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationPapers & Research
GitHubbombobombone/cve-2026-73309

CVE-2026-73309

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty client-secret and PKCE verification bypass with a Python script.

عرض المستودع
120منذ 20 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

CVE-2026-73309: Empty OAuth2 credentials bypass

XenForo before 2.3.13 can skip OAuth2 client-secret and PKCE verification when an empty string reaches the token endpoint.

What happens

The endpoint checks whether client_secret and code_verifier keys exist, then performs the comparisons only when their PHP string values are truthy. An empty value therefore satisfies the presence check but bypasses the comparison.

For a public OAuth client, an attacker still needs a valid authorization code. The bug removes the PKCE guarantee that the code alone is insufficient: the code can be exchanged without the verifier, producing tokens with the scopes approved by the user. The same falsey-value pattern affected confidential-client checks.

I reproduced the issue on XenForo 2.3.12 (build 2031270). XenForo 2.3.13 contains the fix.

Proof of concept

The script performs one token exchange with an empty code_verifier and checks whether the returned access token works.

root@kitploit:~
python poc.py https://xenforo.example CLIENT_ID AUTHORIZATION_CODE https://client.example/callback

A vulnerable installation returns HTTP 200 from the token endpoint and an authenticated response from /api/me. A fixed installation rejects the exchange.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

تنزيل الأداة