nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-35056 CVE-2026-35056
HIGH
XenForo Remote Code Execution via Authenticated Admin
Record summary
CVE-2026-35056 has a selected CVSS score of 8.6 (high).
Description
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 30, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 1, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
XenForoBrowse XenForo / XenForoDefault status: unaffected | CVE List, VulnCheck | 2.3.0 to < 2.3.9 | affected |
| Before 2.2.18 | affected |
References
3VulnCheck Advisory: XenForo Remote Code Execution via Authenticated AdminThird-party advisory
https://www.vulncheck.com/advisories/xenforo-remote-code-execution-via-authenticated-admin XenForo 2.3.9 (inc XFMG) & 2.2.18 Released (Security Fix)Vendor advisorypatch
https://xenforo.com/community/threads/xenforo-2-3-9-inc-xfmg-2-2-18-released-security-fix.235659