CVE-2026-73311 is an OAuth 2.0 authorization-code replay vulnerability in XenForo versions before 2.3.13. XenForo does not invalidate or otherwise mark an authorization code as consumed after it has been exchanged for tokens. Consequently, a previously used authorization code can be resubmitted to obtain an additional, independent token pair for the same authorized user and scopes, violating the authorization-code flow's single-use requirement.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains a standalone Python proof of concept for CVE-2026-73311, an OAuth2 authorization-code replay issue in XenForo versions before 2.3.13. The README describes that successfully redeemed codes are not consumed atomically, allowing a party already holding a legitimate authorization code and required client parameters to reuse it; it does not obtain authorization codes itself. poc.py accepts a target base URL, client ID, code, and redirect URI, with optional PKCE verifier and client secret. It POSTs the same form-encoded grant twice to /api/oauth2/token, hashes and compares the returned access tokens, and uses both as Bearer credentials against /api/me. A target is considered vulnerable only if both exchanges return HTTP 200, produce different nonempty access tokens, and both tokens authenticate successfully. .gitignore only excludes Python bytecode/cache files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An OAuth2 authorization-code reuse vulnerability in XenForo versions before 2.3.13. Because authorization codes are not invalidated or marked consumed after token issuance, an attacker can reuse a code to obtain an independent token pair for the same user and scopes, bypassing the OAuth2 single-use guarantee.
An OAuth2 authorization-code reuse vulnerability in XenForo versions before 2.3.13. Authorization codes are not invalidated or marked consumed after token issuance, allowing reuse to obtain independent token pairs for the same user and scopes and bypassing OAuth2's single-use-code guarantee.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.