PT-2026-30950 · Unknown · Parse Server

Offset

·

Published

2026-04-07

·

Updated

2026-04-09

·

CVE-2026-39321

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.8.0-alpha.6 and prior to 8.6.74
Description The timing difference in the response time of the login endpoint allows an unauthenticated attacker to enumerate valid usernames. When a user is not found, the server responds immediately. When a user exists but the password is incorrect, a bcrypt comparison adds significant latency. This timing difference can be exploited to identify valid usernames.
Recommendations Update to Parse Server version 9.8.0-alpha.6 or later. Update to Parse Server version 8.6.74 or later.

Fix

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-39321
CVE-2026-39321
GHSA-MMPQ-5HCV-HF2V

Affected Products

Parse Server