CVE-2026-32248 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 13, 2026
Parse Server - Authentication Bypass
Overview
Parse Server < 9.6.0-alpha.12 and < 8.6.38 contains an authentication bypass caused by crafted login requests triggering pattern-matching queries instead of exact-match lookups, letting unauthenticated attackers take over user accounts with vulnerable authentication providers, exploit requires anonymous authentication enabled.
Severity & Score
Impact
Unauthenticated attackers can take over user accounts and obtain valid session tokens, leading to full account compromise.
Mitigation
Update to version 9.6.0-alpha.12, 8.6.38 or later.
References
Social Media Activity(3 posts)
š“ CVE-2026-32248 - Critical (9.8) Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider... š https://www.thehackerwire.com/vulnerability/CVE-2026-32248/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-32248 - Critical (9.8) Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider... š https://www.thehackerwire.com/vulnerability/CVE-2026-32248/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postšØ CRITICAL: CVE-2026-32248 in parse-server (>=9.0.0, <9.6.0-alpha.12, <8.6.38) allows unauth attackers to hijack accounts if anonymous auth is enabled. MongoDB & PostgreSQL affected. Upgrade ASAP or disable anonymous auth! https://radar.offseq.com/threat/cve-2026-32248-cwe-943-improper-neutralization-of--cc26229b #OffSeq #CVE202632248 #infosec
View original postRelated Resources
Details
- CVE ID
- CVE-2026-32248
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- broken_authentication
- Status
- confirmed
- EPSS
- 7.1%
- Social Posts
- 3
CWE
- CWE-943
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H