Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2026-73309 — Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty client-secret and PKCE verification bypass with a Python script. | Kitploit
Ferramentas/GitHubGitHub/bombobombone/cve-2026-73309
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationPapers & Research
GitHubbombobombone/cve-2026-73309

CVE-2026-73309

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty client-secret and PKCE verification bypass with a Python script.

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Ver Repositório
120há 20 diasAinda não revisado
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

CVE-2026-73309: Empty OAuth2 credentials bypass

XenForo before 2.3.13 can skip OAuth2 client-secret and PKCE verification when an empty string reaches the token endpoint.

What happens

The endpoint checks whether client_secret and code_verifier keys exist, then performs the comparisons only when their PHP string values are truthy. An empty value therefore satisfies the presence check but bypasses the comparison.

For a public OAuth client, an attacker still needs a valid authorization code. The bug removes the PKCE guarantee that the code alone is insufficient: the code can be exchanged without the verifier, producing tokens with the scopes approved by the user. The same falsey-value pattern affected confidential-client checks.

I reproduced the issue on XenForo 2.3.12 (build 2031270). XenForo 2.3.13 contains the fix.

Proof of concept

The script performs one token exchange with an empty code_verifier and checks whether the returned access token works.

root@kitploit:~
python poc.py https://xenforo.example CLIENT_ID AUTHORIZATION_CODE https://client.example/callback

A vulnerable installation returns HTTP 200 from the token endpoint and an authenticated response from /api/me. A fixed installation rejects the exchange.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

Baixar ferramenta