PT-2026-29278 · Unknown · Parse Server

Bugbunny-Research

·

Published

2026-03-31

·

Updated

2026-04-06

·

CVE-2026-34574

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 8.6.69 and 9.7.0-alpha.14
Description An authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the session update endpoint. This allows nullifying the session expiry, making the session valid indefinitely and bypassing configured session length policies. The truthiness-based guard checks were replaced with key-presence checks that reject any value for protected session fields, including null.
Recommendations Update to version 8.6.69 or 9.7.0-alpha.14.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-34574
CVE-2026-34574
GHSA-F6J3-W9V3-CQ22

Affected Products

Parse Server