PT-2026-23438 · Unknown · Parse Server
Asukachloe
+1
·
Published
2026-03-05
·
Updated
2026-03-11
·
CVE-2026-29182
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Parse Server versions prior to 8.6.4
Parse Server versions prior to 9.4.1-alpha.3
Description
Parse Server deployments utilizing the
readOnlyMasterKey option are susceptible to unauthorized modifications. The readOnlyMasterKey is intended to grant read-only access, but certain endpoints incorrectly permit mutating operations when using this key. This allows an attacker possessing the readOnlyMasterKey to create, modify, and delete Cloud Hooks and initiate Cloud Jobs, potentially leading to data exfiltration. The vulnerable endpoints incorrectly process the readOnlyMasterKey for operations that should be restricted. The readOnlyMasterKey variable is misused in authorization checks.Recommendations
Parse Server versions prior to 8.6.4 should be upgraded to version 8.6.4 or later.
Parse Server versions prior to 9.4.1-alpha.3 should be upgraded to version 9.4.1-alpha.3 or later.
If upgrading is not immediately possible, ensure the
readOnlyMasterKey value is not shared with untrusted parties.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parse Server