---
id: CVE-2026-73317
title: >-
  XenForo before 2.3.13 contains a missing authorization vulnerability in the
  ACP cache-rebuild dispatcher that allows limited administrators with only the
  rebuildCache permission to perform unauthorized approval queue actions by
  supplying…
summary: >-
  XenForo before 2.3.13 contains a missing authorization vulnerability in the
  ACP cache-rebuild dispatcher that allows limited administrators with only the
  rebuildCache permission to perform unauthorized approval queue actions by
  supplying…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
vendor: xenforo
product: xenforo
affected:
  - xenforo < 2.3.13
patched:
  - xenforo 2.3.13
published: '2026-09-08'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T20:26:12.553'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73317'
references:
  - url: 'https://bombobombone.github.io/posts/cve-2026-73317/'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/BomboBombone/CVE-2026-73317'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/xenforo-missing-authorization-via-acp-cache-rebuild-dispatcher
    label: disclosure@vulncheck.com
  - url: >-
      https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-and-media-gallery-versions-2-2-0-2-3-12.239856/
    label: disclosure@vulncheck.com
  - url: >-
      https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includes-security-fixes.239857/
    label: disclosure@vulncheck.com
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00408
epssPercentile: 0.32304
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/BomboBombone/CVE-2026-73317'
  checkedAt: '2026-09-26T09:05:58.809Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T13:59:17.987820Z'
ingestedAt: '2026-09-08T15:33:26.984Z'
---

## Overview

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. Attackers can invoke the approval queue job under any user identity to approve queued user registrations without holding the required approval-queue or moderator permissions, causing the moderation log to attribute actions to an impersonated account.

## Affected

- `xenforo < 2.3.13`

## Remediation

Upgrade past the affected range:

- `xenforo 2.3.13`
