Executive brief
Parse Server is a backend service that provides database and authentication services for mobile applications. A flaw in the /loginAs endpoint allows holders of a read-only API credential to impersonate any user and gain full read-write access to their data. Any organization using Parse Server's read-only master key feature is at risk of unauthorized data access and modification.
Technical details
The vulnerability is an authorization bypass in Parse Server's /loginAs endpoint that fails to properly validate privilege levels. An attacker with a readOnlyMasterKey can call POST /loginAs to obtain a valid session token for any arbitrary user, bypassing the intended read-only restrictions (CWE-863: Improper Authorization). The attack requires network access and prior possession of the readOnlyMasterKey credential. Successful exploitation enables full read and write access to any user's data. Patches are available in Parse Server 8.6.6 and 9.5.0-alpha.4.
Affected products
- Parse Community Parse Server < 8.6.6, >= 9.0.0 and < 9.5.0-alpha.4
Timeline
- 2026-03-06: disclosed
- 2026-03-06: patched: Parse Server 8.6.6 and 9.5.0-alpha.4