PT-2026-25058 · Bitnami+4 · Parse+1

Fancymalware

·

Publicado

2026-03-12

·

Atualizado

2026-03-17

·

CVE-2026-32248

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.6.0-alpha.12 and 8.6.38
Description Parse Server, an open-source backend deployable on Node.js infrastructures, is susceptible to account takeover. An unauthenticated attacker can compromise user accounts created with authentication providers that do not validate user identifiers, such as those using anonymous authentication. By submitting a specially crafted login request, the attacker can manipulate the server into performing a pattern-matching query instead of an exact-match lookup. This allows the attacker to successfully match an existing user and obtain a valid session token, effectively gaining control of the user's account. Both MongoDB and PostgreSQL database backends are affected. The issue stems from insufficient input validation for authentication data, specifically the user identifier. The fix involves enforcing that the user identifier is a string before use in database queries, rejecting non-string values.
Recommendations Versions prior to 9.6.0-alpha.12 should be updated to 9.6.0-alpha.12 or later. Versions prior to 8.6.38 should be updated to 8.6.38 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-PARSE-2026-32248
CVE-2026-32248
GHSA-5FW2-8JCV-XH87

Produtos afetados

Parse
Parse Server