CVE-2026-32878Disclosure(parseplatform / parse-server)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch parseplatform parse-server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.20 and 8.6.44, an attacker can bypass the default request keyword denylist protection and the class-level permission for adding fields by sending a crafted request that exploits prototype pollution in the deep copy mechanism. This allows injecting fields into class schemas that have field addition locked down, and can cause permanent schema type conflicts that cannot be resolved even with the master key. In 9.6.0-alpha.20 and 8.6.44, the vulnerable third-party deep copy library has been replaced with a built-in deep clone mechanism that handles prototype properties safely, allowing the existing denylist check to correctly detect and reject the prohibited keyword. No known workarounds are available.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-03-19)
  • 5 total mentions across 2 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-18: 1Mentions · 2026-03-19: 4Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-03-19: 2Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 203-1803-19
Signal classification2 categories
Disclosure
480.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-181
Disclosure1
2026-03-194
Active Exploitation1Disclosure3
Full discourse5 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-32878 - parse-community - parse-server - https://www.redpacketsecurity.com/cve-alert-cve-2026-32878-parse-community-parse-server/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32878 #parse-community #parse-server

    Post summary

    The post announces a CVE-2026-32878 alert for the parse-server component of parse-community, but offers no technical details, PoC, or exploitation evidence.

    0000074
    3.6K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Google warns iPhone users about a new exploit kit used by spyware vendors and suspected state actors to plant info-stealing malware. CISA adds CVE-2025-66376 affecting Synacor Zimbra Collabora to its Known Exploited Vulnerabilities Catalog due to active exploitation. Micropatches released for Microsoft Access remote code execution vulnerability (CVE-2025-62552) to prevent unauthorized code execution. Parse Server vulnerable to schema poisoning via prototype pollution (CVE-2026-32878), allowing attackers to bypass protections. Stay sharp. Stay secure. #NerdieNews #CyberSecurity #InfoSec #ThreatIntel #APT

    Post summary

    The post reports that CVE‑2025‑66376 is actively exploited, a patch was released for CVE‑2025‑62552, and Parse Server is vulnerable to prototype pollution (CVE‑2026‑32878), underscoring current risks and mitigations.

    00000115
    49 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32878 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.20 and 8.6.44, an attacker can bypass the… https://www.cve.org/CVERecord?id=CVE-2026-32878

    Post summary

    The post discloses CVE-2026-32878—a Parse Server vulnerability that allows attackers to bypass restrictions in versions before 9.6.0-alpha.20 and 8.6.44, with a link to the CVE record for further details.

    00000141
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32878 Prototype Pollution Vulnerability in Parse Server Enabling Unauthorized Schema Modification https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32878

    Post summary

    The post announces a prototype‐pollution flaw in Parse Server that allows unauthorized schema changes, linking to a vulnerability details page.

    0000045
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Parse Server, Prototype Pollution, #CVE-2026-32878 (Moderate) https://dailycve.com/parse-server-prototype-pollution-cve-2026-32878-moderate/

    Post summary

    CVE‑2026‑32878 is a prototype pollution flaw in Parse Server, publicly disclosed with moderate severity, but no PoC, exploit, patch, or active exploitation details are supplied.

    0000026
    169 followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-

Explore more