CRITICAL🇵🇱 Wersja polska

CVE-2026-32248

CVSS 9.3v4.0pub. 2026-03-12upd. 2026-03-13

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider that does not validate the format of the user identifier (e.g. anonymous authentication). By sending a crafted login request, the attacker can cause the server to perform a pattern-matching query instead of an exact-match lookup, allowing the attacker to match an existing user and obtain a valid session token for that user's account. Both MongoDB and PostgreSQL database backends are affected. Any Parse Server deployment that allows anonymous authentication (enabled by default) is vulnerable. This vulnerability is fixed in 9.6.0-alpha.12 and 8.6.38.

🤖 AI Analysis
How it works

An attacker sends a crafted login request that causes the server to execute a pattern-matching query instead of an exact-match lookup. This results from improper input handling in the database query layer (CWE-943 — improper neutralization of special elements in data query). This allows the attacker to match an existing user account and obtain a valid session token without knowing the password. The issue affects both MongoDB and PostgreSQL backends.

Impact

An attacker obtains a valid session token for a selected user account, enabling complete account takeover and impersonation. This can lead to unauthorized data access and privilege escalation in applications using Parse Server.

Mitigation & patch

Parse Server must be updated to version 8.6.38 or 9.6.0-alpha.12 (or newer). Details available in vendor references: https://github.com/parse-community/parse-server/releases/tag/8.6.38 and https://github.com/parse-community/parse-server/releases/tag/9.6.0-alpha.12. Until the patch is implemented, consider disabling anonymous authentication if not required by the application.

Who is affected

Parse Server (parseplatform/parse-server) in versions prior to 8.6.38 and prior to 9.6.0-alpha.12, with anonymous authentication enabled (active by default). Affects deployments using MongoDB or PostgreSQL databases.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Parseplatform Parse Server

    APP
    Parseplatform
    9.6.0< 8.6.389.0.0 – 9.6.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-34532CRITICAL9.1PL ✓same product

Parse Server: obejście walidatorów Cloud Functions przez prototype chain

CVE-2026-32242CRITICAL9.1PL ✓same product

Race condition w Parse Server — błędna walidacja tokenów OAuth2

CVE-2026-31840CRITICAL9.3PL ✓same product

SQL Injection w Parse Server poprzez dot-notation i parametr sort (PostgreSQL)

CVE-2026-31871CRITICAL9.3PL ✓same product

SQL Injection w Parse Server (PostgreSQL) — operacje Increment na polach zagnieżdżonych

CVE-2026-31856CRITICAL9.3PL ✓same product

SQL Injection w Parse Server (PostgreSQL) — operacje Increment na zagnieżdżonych polach