CVE-2026-31828Patch(parseplatform / parse-server)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) is interpolated directly into LDAP Distinguished Names (DN) and group search filters without escaping special characters. This allows an attacker with valid LDAP credentials to manipulate the bind DN structure and to bypass group membership checks. This enables privilege escalation from any authenticated LDAP user to a member of any restricted group. The vulnerability affects Parse Server deployments that use the LDAP authentication adapter with group-based access control. This vulnerability is fixed in 9.5.2-alpha.13 and 8.6.26.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-10: 103-1003-11
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-101
Patch1
2026-03-111
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-31828 LDAP Injection Vulnerability in Parse Server Authentication Adapter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31828

    Post summary

    The entry only cites the CVE number, a brief title, and a link, offering no actionable details.

    0001029
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31828 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication ad… https://www.cve.org/CVERecord?id=CVE-2026-31828

    Post summary

    The content highlights that Parse Server versions before 9.5.2-alpha.13 and 8.6.26 are vulnerable to an LDAP authentication issue, pointing to a patch but not providing exploit details.

    0000084
    56.7K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-
Appparseplatformparse-server9.5.2node.js-

Explore more