Record summary

CVE-2026-35056 has a selected CVSS score of 8.6 (high).

Description

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 30, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 1, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List, VulnCheck2.3.0 to < 2.3.9affected
Before 2.2.18affected

References

3