XenForo Passkey Authentication Security Bypass Vulnerability

Vulnerability

A security vulnerability has been identified in XenForo versions prior to 2.3.7, affecting Passkey-based authentication. This issue allows an attacker to compromise the security of Passkeys associated with user accounts.

Impact

Exploitation of this vulnerability could lead to unauthorized access or manipulation of Passkey-based authentication, potentially allowing attackers to impersonate users or gain unauthorized privileges.

Remediation

Users are advised to upgrade to XenForo version 2.3.7 or apply the available patch. Instructions for upgrading are available in the XenForo 2 Manual. XenForo Cloud customers will receive the upgrade automatically.

Added: Apr 1, 2026, 1:25 AM
Updated: Apr 1, 2026, 1:25 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
7.2
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.