Junglewise Threat Intelligence

CVE-2026-30941: Parse Server NoSQL injection in password reset and email verification

CVE-2026-30941 · Severity: medium · CVSS 4 · Published 2026-03-11

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is a popular backend-as-a-service platform that handles user authentication, including password resets and email verification. A NoSQL injection vulnerability allows attackers to bypass security checks and extract password reset and email verification tokens without authentication, potentially allowing unauthorized account access and email verification without legitimate inbox access.

Technical details

The vulnerability is a NoSQL injection (CWE-943) in the password reset and email verification resend endpoints. The token parameter is passed directly to MongoDB database queries without type validation, allowing an attacker to inject MongoDB query operators. An unauthenticated, network-based attacker can exploit this to extract password reset and email verification tokens. When emailVerifyTokenReuseIfValid is enabled, the extracted email verification token can be used to verify email addresses without mailbox access. Patches are available: Parse Server 8.6.14 and 9.5.2-alpha.1.

Affected products

  • Parse Community Parse Server < 8.6.14 and >= 9.0.0 < 9.5.2-alpha.1

Timeline

  • 2026-03-10: disclosed
  • 2026-03: patched: Parse Server 8.6.14 and 9.5.2-alpha.1

References