CVE-2026-30966Disclosure(parseplatform / parse-server)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be directly accessed via the REST API or GraphQL API by any client using only the application key. No master key is required. An attacker can create, read, update, or delete records in any internal relationship table. Exploiting this allows the attacker to inject themselves into any Parse Role, gaining all permissions associated with that role, including full read, write, and delete access to classes protected by role-based Class-Level Permissions (CLP). Similarly, writing to any such table that backs a Relation field used in a pointerFields CLP bypasses that access control. This vulnerability is fixed in 9.5.2-alpha.7 and 8.6.20.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-10: 2Mentions · 2026-03-11: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 103-1003-11
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-102
Disclosure1General1
2026-03-111
Disclosure1
Full discourse3 posts
  • maru@maru1151157
    Disclosure

    🚨 CVE-2026-30966 (CVSS: 10.0) Parse Server 9.5.2-alpha.7 以降、8.6.20 以降でない場合、アプリケーションキーのみで内部テーブルへのアクセスが可能で、役割メンバーシップの変更により全権限取得可能。 https://maruomosquit.com/vulnerability/CVE-2026-30966/ #脆弱性 #セキュリティ

    Post summary

    The tweet publicly discloses CVE‑2026‑30966, describing how Parse Server’s application key can be abused for internal table access and privilege escalation, but offers no PoC, exploit tool, active attack evidence, or patch information.

    0000087
    1.8K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-30966 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tab… https://www.cve.org/CVERecord?id=CVE-2026-30966

    Post summary

    The text references a CVE record for Parse Server with version information but provides no further technical details, exploit information, or mitigation steps.

    00000178
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-30966: CRITICAL] Vulnerability in Parse Server versions before 9.5.2-alpha.7 and 8.6.20 allows unauthorized access to internal tables, leading to potential injection and bypass of access controls. ...#cve,CVE-2026-30966,#cybersecurity https://cvefind.com/CVE-2026-30966

    Post summary

    The tweet announces a critical vulnerability in Parse Server versions before 9.5.2-alpha.7 and 8.6.20 that allows unauthorized database access and potential injection, without providing a PoC, exploit, or patch information.

    0000037
    601 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-

Explore more