PT-2026-23753 · Unknown · Parse Server

Devanshbatham

·

Published

2026-03-06

·

Updated

2026-03-11

·

CVE-2026-30229

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 8.6.6 Parse Server versions prior to 9.5.0-alpha.4
Description Parse Server is an open-source backend deployable on Node.js infrastructures. A read-only master key can be used to call the POST /loginAs API endpoint, allowing the creation of a valid session token for any user. This enables a read-only credential to impersonate any user, gaining full read and write access to their data. Any Parse Server deployment utilizing the readOnlyMasterKey is potentially affected. The fix involves adding a check to the /logInAs handler.
Recommendations Versions prior to 8.6.6 should be updated to version 8.6.6 or later. Versions prior to 9.5.0-alpha.4 should be updated to version 9.5.0-alpha.4 or later. As a workaround, avoid using the readOnlyMasterKey.

Exploit

Fix

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-30229
CVE-2026-30229
GHSA-79WJ-8RQV-JVP5

Affected Products

Parse Server