CVE-2026-30228Disclosure(parseplatform / parse-server)

LOWCVSS 4.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.5 and 9.5.0-alpha.3, the readOnlyMasterKey can be used to create and delete files via the Files API (POST /files/:filename, DELETE /files/:filename). This bypasses the read-only restriction which violates the access scope of the readOnlyMasterKey. Any Parse Server deployment that uses readOnlyMasterKey and exposes the Files API is affected. An attacker with access to the readOnlyMasterKey can upload arbitrary files or delete existing files. This issue has been patched in versions 8.6.5 and 9.5.0-alpha.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-07)
  • 5 total mentions across 2 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-06: 2Mentions · 2026-03-07: 3Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-06: 203-0603-07
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure2
2026-03-073
General2Patch1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-30228 Parse Server Files API Vulnerability via Unauthorized ReadOnlyMasterKey Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30228

    Post summary

    A brief reference to CVE-2026-30228, a Parse Server Files API vulnerability involving unauthorized ReadOnlyMasterKey access, is provided without details on PoC, exploitation, patches, or technical specifics.

    0101059
    4.0K followersView on X
  • Devansh (⚡, 🥷)@0xAsm0d3us
    General

    CVE-2026-30228 (missed from original caption)

    Post summary

    The snippet merely identifies CVE‑2026‑30228 without providing any additional context or details.

    00010606
    16.7K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-30228 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.5 and 9.5.0-alpha.3, the readOnlyMasterK… https://www.cve.org/CVERecord?id=CVE-2026-30228

    Post summary

    The text announces that CVE-2026-30228 affects earlier Parse Server releases, and notes that versions 8.6.5 and 9.5.0‑alpha.3 include a fix.

    00000112
    56.6K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Parse Server, File Creation/Deletion Bypass, #CVE-2026-30228 (Moderate) https://dailycve.com/parse-server-file-creation-deletion-bypass-cve-2026-30228-moderate/

    Post summary

    The post announces a moderate‑severity vulnerability (CVE‑2026‑30228) in Parse Server that allows bypassing file creation/deletion operations, but it does not provide any PoC, exploit, or patch information.

    0000037
    164 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30228 - Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction Intel Report: https://ift.tt/WjNFOsV

    Post summary

    CVE-2026-30228 is disclosed as a bypass of the readOnlyMasterKey write restriction in Parse Server, enabling unauthorized file creation and deletion. No PoC, exploits, or patches are referenced.

    0000042
    343 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-

Explore more