CVE-2026-27804Patch(parseplatform / parse-server)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch parseplatform parse-server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authentication token with `alg: "none"` to log in as any user linked to a Google account, without knowing their credentials. All deployments with Google authentication enabled are affected. The fix in versions 8.6.3 and 9.1.1-alpha.4 hardcodes the expected `RS256` algorithm instead of trusting the JWT header, and replaces the Google adapter's custom key fetcher with `jwks-rsa` which rejects unknown key IDs. As a workaround, dsable Google authentication until upgrading is possible.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327CWE-345

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-26: 4Mentions · 2026-02-27: 1Mentions · 2026-03-03: 1PoC Mentioned / Linked · 2026-03-03: 1Exploit Tool / Code · 2026-03-03: 1Patch / Workaround · 2026-02-26: 3Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 102-2602-2703-03
Signal classification3 categories
Patch
466.7%
Disclosure
116.7%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-264
Disclosure1Patch3
2026-02-271
Patch1
2026-03-031
PoC1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    Parse Server patches a critical 9.1 CVSS vulnerability (CVE-2026-27804). Attackers can forge Google tokens using "alg: none" to hijack any linked user account. #ParseServer #CyberSecurity #JWT #InfoSec #NodeJS #BugBounty #AccountTakeover #CVE #WebDev https://securityonline.info/algorithm-confusion-critical-9-1-flaw-in-parse-server-allows-instant-google-account-takeover/

    Post summary

    Parse Server CVE-2026-27804, a critical 9.1 vulnerability that allows attackers to forge Google tokens via "alg: none", has been patched; the post does not mention active exploitation, PoC, or exploit code.

    10021301
    10.4K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27804: Trust Issues: How a JWT Header Toppled Parse Server Authentication A critical vulnerability in Parse Server's authentication adapters allows for complete Account Takeover (ATO) via JWT algorithm confusion. By trusting the 'alg' header ... https://cvereports.com/reports/CVE-2026-27804

    Post summary

    The post announces a critical JWT algorithm confusion vulnerability in Parse Server that enables account takeover, but it does not provide a PoC, exploit code, or patch information.

    0001049
    32 followersView on X
  • sebsrt@s3bsrt
    PoC

    @Blackstone0123 Yes basically, with a kID that makes it return an undefined signing key. This is the poc https://github.com/sebastianosrt/Public-reports-CVEs/blob/main/CVE-2026-27804.py

    Post summary

    The tweet shares a proof‑of‑concept script demonstrating how CVE‑2026‑27804 can be triggered by a kID that causes an undefined signing key.

    00000240
    654 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Parse Server` (CVE-2026-27804) is vulnerable to account takeover via JWT algorithm confusion in its Google auth adapter. Update to 9.3.1-alpha.4+ for `auth-bypass` mitigation. #parse #infosec https://www.pulsepatch.io/posts/cve-2026-27804-parse-server-jwt-algorithm-confusion

    Post summary

    Parse Server CVE-2026-27804 allows account takeover due to JWT algorithm confusion in the Google auth adapter; updating to 9.3.1-alpha.4+ mitigates the issue.

    0000036
    1 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27804 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated … https://www.cve.org/CVERecord?id=CVE-2026-27804

    Post summary

    The CVE-2026-27804 vulnerability in Parse Server is mitigated by upgrading to versions 8.6.3 or 9.1.1-alpha.4, with no mention of active exploitation or PoC.

    00000141
    56.6K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: parse-server flaw lets attackers forge Google auth tokens! All versions <8.6.3 & <9.1.1-alpha.4 at risk. Upgrade now or disable Google login. Details: https://radar.offseq.com/threat/cve-2026-27804-cwe-327-use-of-a-broken-or-risky-cr-9a87af7c #OffSeq #ParseServer #... https://t.co/vSaioh0Ikm

    Post summary

    The tweet alerts users to a critical Parse Server flaw that permits forging Google authentication tokens, provides affected version details, and urges upgrading or disabling Google login, with a link for further information.

    0000051
    270 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.3.1node.js-
Appparseplatformparse-server9.3.1node.js-
Appparseplatformparse-server9.3.1node.js-

Explore more