PT-2026-22056 · Unknown · Parse Server
Sebastianosrt
·
Published
2026-02-25
·
Updated
2026-03-04
·
CVE-2026-27804
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Parse Server versions prior to 8.6.3
Parse Server versions prior to 9.1.1-alpha.4
Description
Parse Server is susceptible to a security issue where an unauthenticated attacker can create a forged Google authentication token using
alg: "none" to gain access as any user associated with a Google account, without needing their credentials. All deployments utilizing Google authentication are potentially affected. The issue stems from trusting the JWT header and using a custom key fetcher that accepted unknown key IDs.Recommendations
Versions prior to 8.6.3 should be upgraded to version 8.6.3 or later.
Versions prior to 9.1.1-alpha.4 should be upgraded to version 9.1.1-alpha.4 or later.
As a temporary workaround, disable Google authentication until an upgrade is possible.
Exploit
Fix
Insufficient Verification of Data Authenticity
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Parse Server