PT-2026-24690 · Bitnami+4 · Parse+1

0Xkakash1

·

Publicado

2026-03-11

·

Atualizado

2026-03-13

·

CVE-2026-31875

CVSS v4.0

8.2

Alta

VetorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.6.0-alpha.7 Parse Server versions prior to 8.6.33
Description Parse Server, a backend deployable on Node.js infrastructures, is affected by an issue where recovery codes for multi-factor authentication (MFA) via TOTP are not consumed after use. This allows an attacker who obtains a single recovery code to repeatedly authenticate as the affected user without the code being invalidated, undermining the intended single-use design and weakening the security of MFA-protected accounts. The issue arises when MFA via TOTP is enabled for a user account, and Parse Server generates two single-use recovery codes intended as a fallback when a TOTP token is unavailable.
Recommendations Versions prior to 9.6.0-alpha.7 should be updated to version 9.6.0-alpha.7 or later. Versions prior to 8.6.33 should be updated to version 8.6.33 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-PARSE-2026-31875
CVE-2026-31875
GHSA-4HF6-3X24-C9M8

Produtos afetados

Parse
Parse Server