CVE-2026-30229Disclosure(parseplatform / parse-server)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, the readOnlyMasterKey can call POST /loginAs to obtain a valid session token for any user. This allows a read-only credential to impersonate arbitrary users with full read and write access to their data. Any Parse Server deployment that uses readOnlyMasterKey is affected. This issue has been patched in versions 8.6.6 and 9.5.0-alpha.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-07)
  • 4 total mentions across 2 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-06: 1Mentions · 2026-03-07: 3Patch / Workaround · 2026-03-07: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0603-07
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-061
Disclosure1
2026-03-073
Disclosure3
Full discourse4 posts
  • Devansh (⚡, 🥷)@0xAsm0d3us
    Disclosure

    Earlier this month, I found 4 vulnerabilities in parse-server (21k+ stars on GitHub) They've now been assigned CVEs: CVE-2026-29182 CVE-2026-30229 CVE-2026-30863 Disclosing now as all advisories are published and patches are out. Full write up: https://devansh.bearblog.dev/parse-server/ https://t.co/5zbs7gqS10

    Post summary

    The author disclosed three CVEs in parse-server, noting that advisories are published and patches are available.

    5120121697.6K
    16.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30229 Parse Server Privilege Escalation via Unauthorized User Session Token Generation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30229

    Post summary

    CVE-2026-30229 is a privilege escalation vulnerability in Parse Server that allows unauthorized session token generation; details are briefly highlighted and a link to a summary is provided.

    1000056
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30229 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, the readOnlyMasterK… https://www.cve.org/CVERecord?id=CVE-2026-30229

    Post summary

    CVE-2026-30229 was disclosed for Parse Server, with a fix available in versions 8.6.6 and 9.5.0-alpha.4; no exploit or PoC was mentioned.

    00000114
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30229 - Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user Intel Report: https://ift.tt/SwOahFD

    Post summary

    An alert discloses CVE-2026-30229 affecting Parse Server’s `/loginAs` endpoint, allowing an attacker to use a readOnlyMasterKey for full account takeover, but no PoC, exploit, patch, or active exploitation details are provided.

    0000045
    343 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-

Explore more