CVE-2026-32242Disclosure(parseplatform / parse-server)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations. Under concurrent authentication requests for different OAuth2 providers, one provider's token validation may execute using another provider's configuration, potentially allowing a token that should be rejected by one provider to be accepted because it is validated against a different provider's policy. Deployments that configure multiple OAuth2 providers via the oauth2: true flag are affected. This vulnerability is fixed in 9.6.0-alpha.11 and 8.6.37.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-12); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-12: 3Mentions · 2026-03-13: 2Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 2Technical Details · 2026-03-16: 103-1203-1303-16
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-123
Disclosure3
2026-03-132
Disclosure2
2026-03-161
Disclosure1
Full discourse6 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical race condition and session takeover vulnerability in #ParseServer. CVE-2026-32242 CVSS 9.1 CVE-2026-32248 CVSS: 9.3. This vulnerability can lead to a token being accepted by the wrong provider which results in an #ATO. #Patch #Patch #Patch

    Post summary

    The post announces critical race condition and session takeover vulnerabilities (CVE‑2026‑32242, CVE‑2026‑32248) in ParseServer with high CVSS scores, noting that a patch is likely available.

    00001226
    7.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Parse Server`'s OAuth2 adapter has a mutable state vulnerability (CVE-2026-32242), potentially causing cross-provider issues. Review configurations. #ParseServer #OAuth2 #InfoSec https://www.pulsepatch.io/posts/cve-2026-32242-parse-server-oauth2-mutable-state

    Post summary

    The post announces a mutable state vulnerability in Parse Server's OAuth2 adapter (CVE-2026-32242) that could lead to cross-provider issues, urging configuration review.

    0000040
    1 followersView on X
  • Flarestart@flarestartcom
    Disclosure

    CVE-2026-32242: CVE-2026-32242: Authentication Bypass via Race Condition in Parse Server OAuth2 Adapter via http://Dev.to https://flarestart.com/article/cve-2026-32242-cve-2026-32242-authentication-bypass-via-race-condition-in-parse-server-oauth2-adapter-20260313 #DevNews #Security https://t.co/x9kjxzSYmg

    Post summary

    The tweet announces CVE‑2026‑32242, an authentication bypass race‑condition flaw in Parse Server OAuth2 Adapter, and links to an article but provides no evidence of exploitation or mitigation.

    0000028
    27 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Parse Server, Race Condition, #CVE-2026-32242 (Critical) https://dailycve.com/parse-server-race-condition-cve-2026-32242-critical/

    Post summary

    Announcement of a race condition vulnerability in Parse Server (CVE-2026-32242) rated critical, with no evidence of exploits, patches, or active attacks provided.

    0000035
    167 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32242 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OA… https://www.cve.org/CVERecord?id=CVE-2026-32242

    Post summary

    The text announces CVE-2026-32242 for Parse Server, noting affected versions and linking to the CVE record, but provides no additional exploitation, patch, or technical detail.

    00000123
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32242: Parse Server OAuth2 adapter shar... Race condition in Parse Server's OAuth2 singleton lets attackers bypass token validation by exploiting concurrent auth ... https://zerodaysignal.com/vulnerability/CVE-2026-32242 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a race condition in Parse Server’s OAuth2 adapter that can bypass token validation, providing a technical summary but no PoC, exploit, or patch information.

    0000035
    143 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-

Explore more