Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-73309 — Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty client-secret and PKCE verification bypass with a Python script. | Kitploit
Herramientas/GitHubGitHub/bombobombone/cve-2026-73309
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationPapers & Research
GitHubbombobombone/cve-2026-73309

CVE-2026-73309

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty client-secret and PKCE verification bypass with a Python script.

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Ver Repositorio
120hace 20 díasAún no revisado
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

CVE-2026-73309: Empty OAuth2 credentials bypass

XenForo before 2.3.13 can skip OAuth2 client-secret and PKCE verification when an empty string reaches the token endpoint.

What happens

The endpoint checks whether client_secret and code_verifier keys exist, then performs the comparisons only when their PHP string values are truthy. An empty value therefore satisfies the presence check but bypasses the comparison.

For a public OAuth client, an attacker still needs a valid authorization code. The bug removes the PKCE guarantee that the code alone is insufficient: the code can be exchanged without the verifier, producing tokens with the scopes approved by the user. The same falsey-value pattern affected confidential-client checks.

I reproduced the issue on XenForo 2.3.12 (build 2031270). XenForo 2.3.13 contains the fix.

Proof of concept

The script performs one token exchange with an empty code_verifier and checks whether the returned access token works.

root@kitploit:~
python poc.py https://xenforo.example CLIENT_ID AUTHORIZATION_CODE https://client.example/callback

A vulnerable installation returns HTTP 200 from the token endpoint and an authenticated response from /api/me. A fixed installation rejects the exchange.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

Descargar herramienta