CVE-2026-29182Disclosure(parseplatform / parse-server)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Parse Server's readOnlyMasterKey option allows access with master-level read privileges but is documented to deny all write operations. However, some endpoints incorrectly accept the readOnlyMasterKey for mutating operations. This allows a caller who only holds the readOnlyMasterKey to create, modify, and delete Cloud Hooks and to start Cloud Jobs, which can be used for data exfiltration. Any Parse Server deployment that uses the readOnlyMasterKey option is affected. Note than an attacker needs to know the readOnlyMasterKey to exploit this vulnerability. This issue has been patched in versions 8.6.4 and 9.4.1-alpha.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-07); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Mentions · 2026-03-08: 1Patch / Workaround · 2026-03-07: 2Technical Details · 2026-03-06: 103-0603-0703-08
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-061
Disclosure1
2026-03-072
Disclosure2
2026-03-081
General1
Full discourse4 posts
  • Devansh (⚡, 🥷)@0xAsm0d3us
    Disclosure

    Earlier this month, I found 4 vulnerabilities in parse-server (21k+ stars on GitHub) They've now been assigned CVEs: CVE-2026-29182 CVE-2026-30229 CVE-2026-30863 Disclosing now as all advisories are published and patches are out. Full write up: https://devansh.bearblog.dev/parse-server/ https://t.co/5zbs7gqS10

    Post summary

    The author announces the discovery of four CVEs in parse-server, notes that advisories and patches are available, and links to a detailed write‑up.

    5120121697.6K
    16.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2017-0144 3 - CVE-2026-20820 4 - CVE-2026-29182 5 - CVE-2026-20079 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without additional technical details or actionable information.

    01020178
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29182 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Parse Server's read… https://www.cve.org/CVERecord?id=CVE-2026-29182

    Post summary

    The text announces that Parse Server versions prior to 8.6.4 and 9.4.1-alpha.3 are vulnerable (CVE-2026-29182) and points to a CVE record, but provides no exploit details or technical specifics.

    00000119
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29182 - Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction Intel Report: https://ift.tt/qHTtfP8

    Post summary

    The intel report announces CVE-2026-29182, a Parse Server flaw that allows cloud hooks and jobs to bypass the readOnlyMasterKey write restriction.

    0000046
    343 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.4.1node.js-
Appparseplatformparse-server9.4.1node.js-

Explore more