Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-73313 — Proof-of-concept exploit for CVE-2026-73313, an MFA bypass in XenForo's passkey TFA provider allowing account takeover after password compromise. | Kitploit
Outils/GitHubGitHub/bombobombone/cve-2026-73313
Vulnerability AnalysisExploitationWeb SecurityPenetration TestingAuthentication
GitHubbombobombone/cve-2026-73313

CVE-2026-73313

Proof-of-concept exploit for CVE-2026-73313, an MFA bypass in XenForo's passkey TFA provider allowing account takeover after password compromise.

Voir le dépôt
12il y a 20 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

CVE-2026-73313: Passkey credential not bound to login account

XenForo before 2.3.13 can complete one user's two-step login with a passkey owned by a different user.

What happens

The passkey manager performs a global lookup using the credential ID supplied in the assertion and correctly verifies that credential's WebAuthn signature. The TFA provider then reduces the result to a boolean without checking that the credential owner matches the user whose password login is pending.

An attacker who knows a target's correct password can answer the target's passkey challenge with the attacker's own registered passkey. Login completes as the target. The shared flow also affected ACP login when the target was an administrator.

This is an MFA bypass after first-factor compromise, not a passwordless takeover. The attacker needs their own valid passkey, the target's password, and a target account configured for passkey TFA.

I reproduced both public and ACP flows on XenForo 2.3.12 (build 2031270). XenForo 2.3.13 contains the fix.

Proof of concept

Install the dependencies and supply two users plus a passkey registered to the attacker account:

root@kitploit:~
python -m pip install -r requirements.txt
python poc.py https://xenforo.example TARGET_USERNAME ATTACKER_CREDENTIAL_ID attacker-private-key.pem

The target password is read from a prompt. Add --include-acp to test the ACP login flow.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

Télécharger l’outil