XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
Metrics
Affected Vendors & Products
References
History
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server. | |
| Title | XenForo Remote Code Execution via Authenticated Admin | |
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xenforo
Xenforo xenforo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-01T01:43:24.702Z
Reserved: 2026-04-01T00:19:59.194Z
Link: CVE-2026-35056
No data.
Status : Received
Published: 2026-04-01T01:16:41.593
Modified: 2026-04-01T01:16:41.593
Link: CVE-2026-35056
No data.
OpenCVE Enrichment
No data.