
🚨 CVE-2026-30966 (CVSS: 10.0) Parse Server 9.5.2-alpha.7 以降、8.6.20 以降でない場合、アプリケーションキーのみで内部テーブルへのアクセスが可能で、役割メンバーシップの変更により全権限取得可能。 https://maruomosquit.com/vulnerability/CVE-2026-30966/ #脆弱性 #セキュリティ
Post summary
The tweet publicly discloses CVE‑2026‑30966, describing how Parse Server’s application key can be abused for internal table access and privilege escalation, but offers no PoC, exploit tool, active attack evidence, or patch information.


