CVE-2026-32269Disclosure(parseplatform / parse-server)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds are configured. During app ID validation, a malformed value is sent to the token introspection endpoint instead of the user's actual access token. Depending on the introspection endpoint's behavior, this could either cause all OAuth2 logins to fail, or allow authentication from disallowed app contexts if the endpoint returns valid-looking data for the malformed request. Deployments using the OAuth2 adapter with appidField and appIds configured are affected. This vulnerability is fixed in 9.6.0-alpha.13 and 8.6.39.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-683

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 203-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32269 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication … https://www.cve.org/CVERecord?id=CVE-2026-32269

    Post summary

    The post announces CVE-2026-32269 affecting OAuth2 authentication in Parse Server, notes the vulnerable releases, and directs readers to the CVE record for more details.

    00000113
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32269 OAuth2 Authentication Bypass in Parse Server Prior to 9.6.0-alpha.13 and 8.6.39 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32269

    Post summary

    The post references CVE‑2026‑32269 as an OAuth2 authentication bypass in older Parse Server versions, providing the affected releases but no further details such as exploits or patches.

    0000023
    4.0K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-

Explore more