CVE-2026-35056 is a high-severity remote code execution (RCE) vulnerability impacting XenForo versions prior to 2.3.9 and 2.2.18. This flaw allows an authenticated, malicious administrator with admin panel access to execute arbitrary code on the server with low attack complexity. Rated 7.2 CVSS, it poses a high risk to confidentiality, integrity, and availability. Currently, there is no public exploit code available, it is not actively exploited according to CISA's KEV, and media coverage is absent, despite minor community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2.2.18CPE match | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | ||
>= 2.3.0, < 2.3.9CPE match | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | ||
< 2.2.18CPE matchmatch criteria | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.