CVE 7 HIGH

Parse Server: Auth provider validation bypass on login via partial authData_CVE-2026-33409

7 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as any user who has linked a third-party authentication provider, without knowing the user's credentials. The attacker only needs to know the user's provider ID to gain full access to their account, including a valid session token. This affects Parse Server deployments where the server option allowExpiredAuthDataToken is set to true. The default value is false. This issue has been patched in versions 8.6.52 and 9.6.0-alpha.41.

Basic Information

ID CVE-2026-33409
Source GitHub_M
Published Mar 24, 2026 at 18:11
Modified Mar 25, 2026 at 13:39

Affected Product

Vendor parse-community
Product parse-server
Version < 8.6.52
Affected Versions parse-community parse-server < 8.6.52
parse-community parse-server >= 9.0.0, < 9.6.0-alpha.41

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.