Multiple Vulnerabilities Discovered in Parse Server Affecting User Security

Multiple Vulnerabilities Discovered in Parse Server Affecting User Security

First seen 12 Mar 2026, 04:44 UTC Nvd.Nist 57.9

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in Parse Server, an open-source backend for Node.js. CVE-2026-30965 allows attackers to exfiltrate session tokens, potentially leading to account takeovers, affecting users with specific Class-Level Permissions. CVE-2026-30946 enables unauthenticated attackers to exhaust server resources through crafted queries, impacting all deployments using REST or GraphQL APIs. Both vulnerabilities were published on March 10, 2026, and have been addressed in recent updates. The affected versions are prior to 9.5.2-alpha.8 and 8.6.21 for CVE-2026-30965, and before 9.5.2-alpha.2 and 8.6.15 for CVE-2026-30946. Security professionals are urged to apply the patches to mitigate risks.

Key Points: • CVE-2026-30965 allows session token exfiltration, risking account takeovers. • CVE-2026-30946 can exhaust server resources via crafted queries. • Both vulnerabilities have been patched in the latest Parse Server versions.

Timeline

2026-03-10
CVE-2026-30965 published
2026-03-10
CVE-2026-30946 published
2026-03-11
Patches released for both vulnerabilities