Back

HIGH

Parse Server: Auth provider validation bypass on login via partial authData

Published Mar 24, 2026

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as any user who has linked a third-party authentication provider, without knowing the user's credentials. The attacker only needs to know the user's provider ID to gain full access to their account, including a valid session token. This affects Parse Server deployments where the server option allowExpiredAuthDataToken is set to true. The default value is false. This issue has been patched in versions 8.6.52 and 9.6.0-alpha.41.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 24, 2026
Updated Mar 25, 2026
Reserved Mar 19, 2026
CISA Vulnrichment
Updated Mar 25, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Mar 24, 2026
Updated Mar 25, 2026
Exploited since n/a
EUVD-2026-14966 GHSA-PFJ7-WV7C-22PR