Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-73312 — Proof-of-concept and technical write-up for CVE-2026-73312, an OAuth2 refresh token replay vulnerability in XenForo before 2.3.13. Includes a Python script to test for the issue. | Kitploit
أدوات/GitHubGitHub/bombobombone/cve-2026-73312
Vulnerability AnalysisExploitationWeb SecurityAuthenticationPapers & Research
GitHubbombobombone/cve-2026-73312

CVE-2026-73312

Proof-of-concept and technical write-up for CVE-2026-73312, an OAuth2 refresh token replay vulnerability in XenForo before 2.3.13. Includes a Python script to test for the issue.

عرض المستودع
18منذ 20 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

CVE-2026-73312: Refresh token replay after access-token expiry

XenForo before 2.3.13 can leave an OAuth2 refresh token reusable when its parent access token has expired.

What happens

XenForo intentionally lets a refresh token outlive its short-lived access token. During rotation it creates the replacement token family, then asks the parent access-token revoker to consume the old family. That revoker returns early when the access token is expired, before revoking the related refresh token.

The original refresh token can consequently be submitted again, producing another independent token family with the same user and scopes. The attacker must already possess a valid refresh token (and the client secret for a confidential client). The issue extends a compromised credential's useful lifetime; it is not a login bypass or scope escalation by itself.

I reproduced the issue on XenForo 2.3.12 (build 2031270) after allowing the parent access token to expire. XenForo 2.3.13 contains the fix.

Proof of concept

root@kitploit:~
python poc.py https://xenforo.example CLIENT_ID REFRESH_TOKEN --verify-me

The script submits one refresh token twice and reports whether XenForo issued two different access tokens.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

تنزيل الأداة