PT-2026-24802 · Bitnami+4 · Parse+1

0Xkakash1

·

Published

2026-03-11

·

Updated

2026-03-13

·

CVE-2026-31901

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 8.6.34 Parse Server versions prior to 9.6.0-alpha.8
Description Parse Server, an open source backend deployable on Node.js infrastructures, is affected by a user enumeration issue. The /verificationEmailRequest API endpoint returns different error responses based on whether an email address is registered, already verified, or non-existent. An attacker can send requests with various email addresses and analyze the error codes to determine which email addresses are associated with existing user accounts. This issue impacts any Parse Server deployment where email verification is enabled (verifyUserEmails: true). A fix introduces the emailVerifySuccessOnInvalidEmail option, which, when enabled, returns a generic success response for all verification email requests, preventing differentiation between valid, verified, and non-existent email addresses. The fix also includes strengthened input validation for the resetPasswordSuccessOnInvalidEmail option and security checks to warn when enumeration mitigation is disabled.
Recommendations Parse Server versions prior to 8.6.34: Upgrade to version 8.6.34 or later. Parse Server versions prior to 9.6.0-alpha.8: Upgrade to version 9.6.0-alpha.8 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-31901
CVE-2026-31901
GHSA-W54V-HF9P-8856

Affected Products

Parse
Parse Server