CVE-2026-34532Disclosure(parseplatform / parse-server)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch parseplatform parse-server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Function handler is declared using the function keyword and its validator is a plain object or arrow function, the trigger store traversal resolves the handler through its own prototype chain while the validator store fails to mirror this traversal, causing all access control enforcement to be skipped. This allows unauthenticated callers to invoke Cloud Functions that are meant to be protected by validators such as requireUser, requireMaster, or custom validation logic. This issue has been patched in versions 8.6.67 and 9.7.0-alpha.11.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-31); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-03-31: 3Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Mentions · 2026-05-14: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-03-31: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 103-3104-0104-0205-1408-27
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Patch
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-313
Disclosure2Patch1
2026-04-011
Disclosure1
2026-04-021
General1
2026-05-141
General1
2026-08-271
General1
Full discourse7 posts
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-4800

    Post summary

    The content merely lists a series of CVE identifiers without additional context or actionable information.

    2176862729382.1K
    3.1K followersView on X
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    The post merely lists a large number of CVE identifiers with no additional information about exploitation, patches, or technical details.

    30124138.4K
    4.0K followersView on X
  • BugBunny.ai - Vibehacking for Vibecoders@BugBunny_ai
    General

    + CVE-2026-34746 where's the 47?? 😅 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 bunny collected 43 CVEs 🚀

    Post summary

    The post simply enumerates a list of CVE identifiers without providing any additional details about exploitation, patching, or technical characteristics.

    3001431.5K
    2.7K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34532 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can b… https://www.cve.org/CVERecord?id=CVE-2026-34532

    Post summary

    The tweet highlights that earlier versions of Parse Server (before 8.6.67 and 9.7.0‑alpha.11) are vulnerable to CVE‑2026‑34532, implying that the newer releases contain a patch, with no exploit, PoC, or active exploitation referenced.

    0001058
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34532: Parse Server: Cloud function val... JavaScript prototype pollution meets access control - append `.prototype.constructor` to any Parse Server cloud functio... https://zerodaysignal.com/vulnerability/CVE-2026-34532 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new CVE-2026-34532 affecting Parse Server cloud functions via prototype pollution is disclosed, with method details shared through a linked article.

    0001047
    194 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `parse-server` is affected by CVE-2026-34532, a critical cloud function validator bypass via prototype chain traversal. This could enable unauthorized operations. Review validation logic. #parse_server #validationbypass #infosec https://www.pulsepatch.io/posts/cve-2026-34532-parse-server-validator-bypass

    Post summary

    The post discloses that Parse Server is vulnerable to CVE-2026-34532, a critical prototype chain traversal that bypasses validator logic and permits unauthorized operations; no PoC, exploit, or patch info is included.

    0000023
    6 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34532 - Parse Server: Cloud function validator bypass via prototype chain traversal Intel Report: https://ift.tt/Y2n6eit

    Post summary

    An alert has been issued for CVE-2026-34532, a prototype chain traversal vulnerability in Parse Server that bypasses cloud function validation.

    00000155
    281 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-

Explore more