CVE-2026-74239 is a path traversal vulnerability affecting XenForo versions before 2.3.13 on Windows deployments. The style archive importer validates forward-slash traversal but does not adequately handle backslash-based traversal sequences in ZIP archive member names. An authenticated non-super administrator granted style permissions can import a crafted style archive and cause attacker-controlled archive contents to be written outside the intended extraction directory to locations writable by the web-server account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains a Python proof-of-concept for CVE-2026-74239, a Windows-specific path traversal flaw in XenForo style archive imports before 2.3.13. README.md documents the affected versions, prerequisites, and invocation; poc.py is the sole executable component; .gitignore excludes Python bytecode artifacts. The script uses Python standard-library HTTP, cookie, ZIP, multipart, and CSRF-handling functionality. It logs into the XenForo ACP as a delegated style administrator, fetches the style-import CSRF token, and uploads a ZIP containing style.xml plus a malicious upload/..\..\..\style-archive-sentinel.php member. The importer is described as filtering /../ but failing to normalize Windows backslashes, allowing extraction outside its temporary directory. The PoC requires --confirm-write, refuses to overwrite an existing sentinel, and verifies exploitation by requesting the resulting public PHP marker. It is an operational but deliberately constrained validation exploit: its payload and destination filename are fixed, and it demonstrates file write plus PHP execution rather than supplying a shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated path-traversal/arbitrary-file-write vulnerability in XenForo's style archive importer on Windows. A user with style permissions can use backslash traversal sequences in malicious ZIP member names to bypass slash validation, write files to web-server-writable locations such as the web root, and potentially obtain persistent code execution as the web-server account.
An authenticated path-traversal/arbitrary-file-write vulnerability in XenForo's style archive importer on Windows deployments. A user with style permissions can use backslash traversal sequences in malicious ZIP member names to bypass validation and write attacker-controlled bytes outside the extraction directory, potentially into the public web root, resulting in persistent code execution as the web-server account.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.