PT-2026-22056 · Unknown · Parse Server

Sebastianosrt

·

Published

2026-02-25

·

Updated

2026-03-04

·

CVE-2026-27804

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 8.6.3 Parse Server versions prior to 9.1.1-alpha.4
Description Parse Server is susceptible to a security issue where an unauthenticated attacker can create a forged Google authentication token using alg: "none" to gain access as any user associated with a Google account, without needing their credentials. All deployments utilizing Google authentication are potentially affected. The issue stems from trusting the JWT header and using a custom key fetcher that accepted unknown key IDs.
Recommendations Versions prior to 8.6.3 should be upgraded to version 8.6.3 or later. Versions prior to 9.1.1-alpha.4 should be upgraded to version 9.1.1-alpha.4 or later. As a temporary workaround, disable Google authentication until an upgrade is possible.

Exploit

Fix

Insufficient Verification of Data Authenticity

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-27804
CVE-2026-27804
GHSA-4Q3H-VP4R-PRV2

Affected Products

Parse Server