LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32248

CVE-2026-32248 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 13, 2026

Parse Server - Authentication Bypass

Published: March 12, 2026Updated: March 13, 2026Remote Exploitable

Overview

Parse Server < 9.6.0-alpha.12 and < 8.6.38 contains an authentication bypass caused by crafted login requests triggering pattern-matching queries instead of exact-match lookups, letting unauthenticated attackers take over user accounts with vulnerable authentication providers, exploit requires anonymous authentication enabled.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 7.1%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can take over user accounts and obtain valid session tokens, leading to full account compromise.

Mitigation

Update to version 9.6.0-alpha.12, 8.6.38 or later.

Social Media Activity(3 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 13, 2026

šŸ”“ CVE-2026-32248 - Critical (9.8) Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32248/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 13, 2026

šŸ”“ CVE-2026-32248 - Critical (9.8) Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32248/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
Offensive Sequence
Offensive Sequence
@offseq
Mar 13, 2026

🚨 CRITICAL: CVE-2026-32248 in parse-server (>=9.0.0, <9.6.0-alpha.12, <8.6.38) allows unauth attackers to hijack accounts if anonymous auth is enabled. MongoDB & PostgreSQL affected. Upgrade ASAP or disable anonymous auth! https://radar.offseq.com/threat/cve-2026-32248-cwe-943-improper-neutralization-of--cc26229b #OffSeq #CVE202632248 #infosec

View original post

Details

CVE ID
CVE-2026-32248
Severity
Critical
CVSS Score
9.8
Type
broken_authentication
Status
confirmed
EPSS
7.1%
Social Posts
3

CWE

  • CWE-943

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

7.1%Probability of exploitation in the next 30 days