
Proof of concept and technical write-up for CVE-2026-73310, an OAuth2 authorization code redirect URI binding flaw in XenForo before 2.3.13, including reproduction steps and a Python PoC script.
XenForo before 2.3.13 does not bind an OAuth2 authorization code to the redirect URI used when that code was issued.
At the token endpoint, XenForo checks that the submitted redirect_uri is somewhere in the client's allowlist. It does not compare the value with the redirect URI stored on the authorization request. A client with callbacks A and B can therefore authorize through A and redeem the code while claiming B.
An attacker must control or observe a valid code and a different callback already registered to the same client. The bug does not create a code or add a new redirect URI. It weakens the binding between the front-channel authorization and the token exchange.
I reproduced the mismatch on XenForo 2.3.12 (build 2031270): callback A issued the code, callback B exchanged it, and the resulting token authenticated as the authorizing user. XenForo 2.3.13 contains the fix.
python poc.py https://xenforo.example CLIENT_ID AUTHORIZATION_CODE https://client.example/callback-b --code-verifier VERIFIER
Use --client-secret for a confidential client. A vulnerable installation accepts callback B; a fixed installation rejects the mismatch.
Discovered by Marco Paciaroni (BomboBombone).