PT-2026-24227 · Unknown · Parse Server

0Xkakash1

·

Published

2026-03-10

·

Updated

2026-03-18

·

CVE-2026-30941

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 8.6.14 Parse Server versions prior to 9.5.2-alpha.1
Description Parse Server, an open-source backend deployable on Node.js infrastructures, contains a NoSQL injection issue. An unauthenticated attacker can inject MongoDB query operators through the token field in the password reset and email verification resend endpoints. The token value is passed to database queries without type validation, potentially allowing extraction of password reset and email verification tokens. Deployments using MongoDB with email verification or password reset enabled are affected. When emailVerifyTokenReuseIfValid is configured, the email verification token can be fully extracted and used to verify a user's email address without inbox access. The affected API endpoints are the password reset and email verification resend endpoints.
Recommendations Versions prior to 8.6.14 should be updated to version 8.6.14 or later. Versions prior to 9.5.2-alpha.1 should be updated to version 9.5.2-alpha.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-30941
CVE-2026-30941
GHSA-VGJH-HMWF-C588

Affected Products

Parse Server