CVE-2026-30863Disclosure(parseplatform / parse-server)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication adapters use JWT verification to validate identity tokens. When the adapter's audience configuration option is not set (clientId for Google/Apple, appIds for Facebook), JWT verification silently skips audience claim validation. This allows an attacker to use a validly signed JWT issued for a different application to authenticate as any user on the target Parse Server. This issue has been patched in versions 8.6.10 and 9.5.0-alpha.11.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 4 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 7 mentions (2026-03-07); latest day: 1
  • 11 total mentions across 4 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 4d
02457Mentions · 2026-03-07: 7Mentions · 2026-03-09: 1Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-07: 2Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-07: 4Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 103-0703-0903-1003-12
Signal classification2 categories
Disclosure
872.7%
General
327.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-077
Disclosure6General1
2026-03-091
General1
2026-03-102
Disclosure2
2026-03-121
General1
Full discourse11 posts
  • Devansh (⚡, 🥷)@0xAsm0d3us
    Disclosure

    Earlier this month, I found 4 vulnerabilities in parse-server (21k+ stars on GitHub) They've now been assigned CVEs: CVE-2026-29182 CVE-2026-30229 CVE-2026-30863 Disclosing now as all advisories are published and patches are out. Full write up: https://devansh.bearblog.dev/parse-server/ https://t.co/5zbs7gqS10

    Post summary

    The author announced four newly assigned CVEs for parse-server, noting that advisories and patches are available, but no exploit or PoC details are provided.

    5120121697.6K
    16.7K followersView on X
  • Devansh (⚡, 🥷)@0xAsm0d3us
    Disclosure

    A crit I reported to parse-server: CVE-2026-30863 https://t.co/WUl8RJml9U

    Post summary

    The tweet announces that a critical vulnerability (CVE‑2026‑30863) was reported to parse‑server, but provides no further technical or exploit details.

    15050193.2K
    16.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30863 - Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters Intel Report: https://ift.tt/FBfhemq

    Post summary

    The alert announces CVE‑2026‑30863, detailing a JWT audience validation bypass in Parse Server’s authentication adapters, without providing PoC or active exploitation evidence.

    0001147
    344 followersView on X
  • Grok@grok
    General

    @spainfunk بنية منصة X لا تعتمد على Parse Server (المنتج المصاب بهذه الثغرة في JWT audience validation). لذلك، هي محصنة تماماً من CVE-2026-30863، ولا توجد أي تقارير أو مؤشرات على تعرضها غير مباشر. X تستخدم بنية داخلية مخصصة (Scala/Java/Kafka) مع طبقات أمان متعددة مستقلة.

    Post summary

    The post states that X’s architecture does not use Parse Server, the product affected by CVE‑2026‑30863, and therefore X is fully protected with no reported exposure.

    0001051
    8.4M followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30863 Authentication Bypass in Parse Server OAuth Adapters via JWT Validation Flaw https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30863

    Post summary

    The post announces a new authentication bypass vulnerability (CVE‑2026‑30863) involving a JWT validation flaw in Parse Server OAuth adapters, with no additional PoC, exploit, or mitigation details shared.

    0001051
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30863 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple… https://www.cve.org/CVERecord?id=CVE-2026-30863

    Post summary

    The post identifies CVE‑2026‑30863 affecting Parse Server before versions 8.6.10 and 9.5.0‑alpha.11, provides a link to the CVE record, and implies an upgrade workaround, but offers no PoC, exploit code, or evidence of active exploitation.

    0001099
    56.6K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30863: Parse Server: JWT audience valid... Silent audience validation bypass lets attackers hijack any Parse Server account with stolen OAuth JWTs from other apps... https://zerodaysignal.com/vulnerability/CVE-2026-30863 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses a new CVE-2026-30863 vulnerability in Parse Server, highlighting a silent audience validation bypass that could let attackers hijack accounts using stolen OAuth JWTs.

    0001088
    140 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-30863 (CVSS:9.3, CRITICAL) is Analyzed. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version..https://nvd.nist.gov/vuln/detail/CVE-2026-30863 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A brief post mentions CVE-2026-30863 with its CVSS score of 9.3 and a link to the NVD entry, but provides no further analysis or details.

    0000017
    172 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30863 - Critical Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authen... https://www.thehackerwire.com/vulnerability/CVE-2026-30863/ https://t.co/oTM0LDhKfz

    Post summary

    CVE-2026-30863 is a critical vulnerability disclosed for Parse Server, with patched versions 8.6.10 and 9.5.0-alpha.11 noted.

    0000047
    133 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `parse-server` is affected by CVE-2026-30863, a JWT audience validation bypass in Google, Apple, and Facebook authentication adapters, risking unauthorized access. #parse_server #JWT #infosec https://www.pulsepatch.io/posts/cve-2026-30863-parse-server-jwt-audience-validation-bypass

    Post summary

    CVE-2026-30863 is a JWT audience validation bypass affecting parse-server adapters for major identity providers, allowing potential unauthorized access, with technical details disclosed but no exploit, patch, or active exploitation information given.

    0000049
    1 followersView on X
  • DailyCVE@dailycve
    General

    🔴 Parse Server, JWT Audience Validation Bypass, #CVE-2026-30863 (Critical) https://dailycve.com/parse-server-jwt-audience-validation-bypass-cve-2026-30863-critical/

    Post summary

    The post merely announces a critical Parse Server vulnerability (#CVE-2026-30863) involving a JWT audience validation bypass, with no further technical depth, PoC, or mitigation disclosed.

    0000029
    166 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-
Appparseplatformparse-server9.5.0node.js-

Explore more