CVE-2026-30965Disclosure(parseplatform / parse-server)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiting the redirectClassNameForKey query parameter. Exfiltrated session tokens can be used to take over user accounts. The vulnerability requires the attacker to be able to create or update an object with a new relation field, which depends on the Class-Level Permissions of at least one class. This vulnerability is fixed in 9.5.2-alpha.8 and 8.6.21.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-10: 1Mentions · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-13: 1Technical Details · 2026-03-10: 1Technical Details · 2026-08-13: 103-1008-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-30965 - critical 🚨 Parse Server < 8.6.21 / 9.x < 9.5.2 - Session Token Exfiltration > Parse Server < 8.6.21 / 9.x < 9.5.2 contains an information disclosure vulnerability ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-30965 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2026‑30965 as a critical information‑disclosure flaw in Parse Server versions <8.6.21/9.x <9.5.2, provides version ranges, and links to a detection template but gives no exploit, active use, or patch details.

    020182670
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30965 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Se… https://www.cve.org/CVERecord?id=CVE-2026-30965

    Post summary

    The text announces a vulnerability in Parse Server affecting versions prior to 9.5.2‑alpha.8 and 8.6.21, but provides no exploit or mitigation details.

    00000145
    56.7K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-

Explore more