CVE-2026-34373Disclosure(parseplatform / parse-server)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionally allows cross-origin requests from any website. This bypasses origin restrictions that operators configure to control which websites can interact with the Parse Server API. The REST API correctly enforces the configured allowOrigin restriction. This issue has been patched in versions 8.6.66 and 9.7.0-alpha.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-31: 2Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 103-31
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34373 - Parse Server: GraphQL API endpoint ignores CORS origin restriction Intel Report: https://ift.tt/lQbrxGq

    Post summary

    An alert for CVE-2026-34373 highlights a CORS bypass in Parse Server’s GraphQL endpoint; no PoC, exploit, patch, or active exploitation details are provided.

    00000190
    281 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34373 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API e… https://www.cve.org/CVERecord?id=CVE-2026-34373

    Post summary

    The text notes CVE-2026-34373 affecting Parse Server’s GraphQL API, indicating that versions prior to 8.6.66 and 9.7.0‑alpha.10 are affected and that newer releases contain a fix.

    0000049
    56.9K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-

Explore more