CVE-2026-32248Disclosure(parseplatform / parse-server)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider that does not validate the format of the user identifier (e.g. anonymous authentication). By sending a crafted login request, the attacker can cause the server to perform a pattern-matching query instead of an exact-match lookup, allowing the attacker to match an existing user and obtain a valid session token for that user's account. Both MongoDB and PostgreSQL database backends are affected. Any Parse Server deployment that allows anonymous authentication (enabled by default) is vulnerable. This vulnerability is fixed in 9.6.0-alpha.12 and 8.6.38.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-12); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-12: 3Mentions · 2026-03-13: 2Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 2Technical Details · 2026-03-17: 103-1203-1303-17
Signal classification1 categories
Disclosure
6100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-123
Disclosure3
2026-03-132
Disclosure2
2026-03-171
Disclosure1
Full discourse6 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical race condition and session takeover vulnerability in #ParseServer. CVE-2026-32242 CVSS 9.1 CVE-2026-32248 CVSS: 9.3. This vulnerability can lead to a token being accepted by the wrong provider which results in an #ATO. #Patch #Patch #Patch

    Post summary

    A critical race condition and session takeover vulnerability in ParseServer (CVE‑2026‑32242 and CVE‑2026‑32248) has been disclosed, with CVSS scores of 9.1 and 9.3 respectively.

    00001226
    7.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Parse Server` is vulnerable to account takeover (CVE-2026-32248) via operator injection in authentication data. Implement robust input validation for auth identifiers. #ParseServer #AppSec #CVE https://www.pulsepatch.io/posts/cve-2026-32248-parse-server-account-takeover

    Post summary

    The post announces a new Parse Server account takeover vulnerability (CVE-2026-32248) caused by operator injection in authentication data and advises implementing input validation mitigations, linking to a detailed article.

    0000035
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32248 - Critical Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any u... https://www.thehackerwire.com/vulnerability/CVE-2026-32248/ https://t.co/KFMTygrtpC

    Post summary

    The post reports a critical vulnerability (CVE-2026-32248) in Parse Server, indicating that versions prior to 9.6.0-alpha.12 and 8.6.38 allow unauthenticated takeover and that updating mitigates the issue.

    0000042
    135 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32248 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacke… https://www.cve.org/CVERecord?id=CVE-2026-32248

    Post summary

    The text announces CVE‑2026‑32248, noting that prior to versions 9.6.0‑alpha.12 and 8.6.38 an unauthenticated attacker can exploit Parse Server, with the referenced link providing the official CVE record.

    00000118
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32248 Unauthenticated Account Takeover in Parse Server via Authentication Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32248

    Post summary

    The post announces CVE-2026-32248, identifying it as an unauthenticated account takeover in Parse Server through an authentication bypass, without mentioning a PoC, exploit code, patch, or active exploitation.

    0000018
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32248: Parse Server: Account takeover v... NoSQL injection through auth provider identifiers turns anonymous login into full account takeover—every Parse deployme... https://zerodaysignal.com/vulnerability/CVE-2026-32248 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-32248, describing a NoSQL injection in Parse Server that enables account takeover via auth provider identifiers, and links to a vulnerability page for more details.

    0000065
    144 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-

Explore more