Multiple Vulnerabilities Discovered in Parse Server Affecting User Security
Article Content
Two critical vulnerabilities have been identified in Parse Server, an open-source backend for Node.js. CVE-2026-30965 allows attackers to exfiltrate session tokens, potentially leading to account takeovers, affecting users with specific Class-Level Permissions. CVE-2026-30946 enables unauthenticated attackers to exhaust server resources through crafted queries, impacting all deployments using REST or GraphQL APIs. Both vulnerabilities were published on March 10, 2026, and have been addressed in recent updates. The affected versions are prior to 9.5.2-alpha.8 and 8.6.21 for CVE-2026-30965, and before 9.5.2-alpha.2 and 8.6.15 for CVE-2026-30946. Security professionals are urged to apply the patches to mitigate risks.
Key Points: • CVE-2026-30965 allows session token exfiltration, risking account takeovers. • CVE-2026-30946 can exhaust server resources via crafted queries. • Both vulnerabilities have been patched in the latest Parse Server versions.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.