CRITICAL🇵🇱 Wersja polska

CVE-2026-32242

CVSS 9.1v4.0pub. 2026-03-12upd. 2026-03-13

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations. Under concurrent authentication requests for different OAuth2 providers, one provider's token validation may execute using another provider's configuration, potentially allowing a token that should be rejected by one provider to be accepted because it is validated against a different provider's policy. Deployments that configure multiple OAuth2 providers via the oauth2: true flag are affected. This vulnerability is fixed in 9.6.0-alpha.11 and 8.6.37.

🤖 AI Analysis
How it works

The built-in OAuth2 adapter in Parse Server exports a single instance (singleton) that is shared by all OAuth2 provider configurations. When authentication requests for different OAuth2 providers arrive at the server simultaneously, a situation may occur where token validation for one provider is performed using the configuration (policy) of another provider. As a result, a token that should be rejected by the correct provider may be incorrectly accepted — because it is verified against another provider's policy. The vulnerability affects only deployments using multiple OAuth2 providers configured with the oauth2: true flag.

Impact

An attacker can gain unauthorized access to a user account or resources protected by Parse Server using an OAuth2 token that would normally be rejected. This results in a breach of data confidentiality and integrity.

Mitigation & patch

Parse Server should be updated to version 8.6.37 (stable branch) or 9.6.0-alpha.11 (alpha branch). Patches are available in the vendor references on GitHub. If immediate updates are not possible, consider limiting the number of concurrent authentication requests or temporarily disabling support for multiple OAuth2 providers.

Who is affected

Parse Server (Parseplatform parse-server) in versions prior to 8.6.37 and prior to 9.6.0-alpha.11, with the vulnerability being active only in a configuration with multiple OAuth2 providers (oauth2: true flag).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Parseplatform Parse Server

    APP
    Parseplatform
    9.6.0< 8.6.379.0.0 – 9.6.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-34532CRITICAL9.1PL ✓same product

Parse Server: obejście walidatorów Cloud Functions przez prototype chain

CVE-2026-32248CRITICAL9.3PL ✓same product

Parse Server — przejęcie konta przez manipulację zapytaniem (Auth Bypass)

CVE-2026-31840CRITICAL9.3PL ✓same product

SQL Injection w Parse Server poprzez dot-notation i parametr sort (PostgreSQL)

CVE-2026-31871CRITICAL9.3PL ✓same product

SQL Injection w Parse Server (PostgreSQL) — operacje Increment na polach zagnieżdżonych

CVE-2026-31856CRITICAL9.3PL ✓same product

SQL Injection w Parse Server (PostgreSQL) — operacje Increment na zagnieżdżonych polach