PT-2026-24690 · Bitnami+4 · Parse+1
0Xkakash1
·
Publicado
2026-03-11
·
Atualizado
2026-03-13
·
CVE-2026-31875
CVSS v4.0
8.2
Alta
| Vetor | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Parse Server versions prior to 9.6.0-alpha.7
Parse Server versions prior to 8.6.33
Description
Parse Server, a backend deployable on Node.js infrastructures, is affected by an issue where recovery codes for multi-factor authentication (MFA) via TOTP are not consumed after use. This allows an attacker who obtains a single recovery code to repeatedly authenticate as the affected user without the code being invalidated, undermining the intended single-use design and weakening the security of MFA-protected accounts. The issue arises when MFA via TOTP is enabled for a user account, and Parse Server generates two single-use recovery codes intended as a fallback when a TOTP token is unavailable.
Recommendations
Versions prior to 9.6.0-alpha.7 should be updated to version 9.6.0-alpha.7 or later.
Versions prior to 8.6.33 should be updated to version 8.6.33 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Parse
Parse Server