Loading
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
Use CWE-94, Xenforo vendor hub and Xenforo product page to widen CVE-2026-35056 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-71279, CVE-2024-38458 and CVE-2024-38457 for nearby disclosures in the same product family.