CVE-2026-35056Disclosure(xenforo / xenforo)

LOWCVSS 8.6 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xenforo

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
xenforo

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-01: 4Technical Details · 2026-04-01: 404-01
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35056 XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execut… https://www.cve.org/CVERecord?id=CVE-2026-35056

    Post summary

    The text announces a remote code execution vulnerability (CVE‑2026‑35056) affecting specific XenForo versions, providing technical detail but no evidence of exploitation, PoC, or patch.

    00000154
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-35056 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-35056 #CVE-2026-35056 #CVE #High #CyberSecurity #InfoSec https://t.co/VCaBLxp0ol

    Post summary

    A newly discovered vulnerability, CVE-2026-35056, is announced with a severity score of 8.8 and high risk level, affecting multiple unspecified products; no PoC, exploit, or patch information is provided.

    0000017
    123 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-35056 - High XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the s... https://www.thehackerwire.com/vulnerability/CVE-2026-35056/ https://t.co/adCx1EeRZk

    Post summary

    High‑severity XenForo remote code execution (CVE‑2026‑35056) allows authenticated admin users to execute arbitrary code in versions prior to 2.3.9 and 2.2.18; detailed CVE information and a reference link are provided.

    0000053
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-35056: HIGH] Critical security vulnerability in XenForo versions before 2.3.9 and 2.2.18 allows admin users to perform remote code execution, posing a serious threat to server security.#cve,CVE-2026-35056,#cybersecurity https://cvefind.com/CVE-2026-35056

    Post summary

    The post discloses a high‑severity remote code execution flaw in XenForo versions prior to 2.3.9 and 2.2.18, noting the risk but providing no evidence of exploitation or mitigation.

    0000061
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxenforoxenforo---

Explore more