Executive brief
Parse Server is a backend-as-a-service platform that manages user authentication and application data. An authentication bypass vulnerability allows attackers to gain unauthorized access to any user account that has linked a third-party authentication provider (such as Google or Facebook) by only knowing the provider ID, bypassing the need to know the actual password. This affects deployments with a specific server configuration option enabled and can lead to complete account takeover.
Technical details
This vulnerability is an authentication bypass (CWE-287) in Parse Server's auth provider validation logic. When the server option `allowExpiredAuthDataToken` is set to true (non-default), the login handler fails to properly validate auth provider credentials, allowing an attacker to impersonate any user with a linked third-party auth provider by submitting partial authData containing only the provider ID. The attack is network-accessible and requires no authentication, but does require knowledge of a target user's provider ID. An attacker gains a valid session token and full account access. The vulnerability was introduced in version 9.0.0 and affects versions 9.0.0–9.6.0-alpha.40 and all versions prior to 8.6.52; patches are available and auth provider validation is now enforced regardless of the configuration option.
Affected products
- Parse Community Parse Server versions 9.0.0 to 9.6.0-alpha.40 and all versions before 8.6.52
Timeline
- 2026-03-19: disclosed
- 2026-03-19: patched: Patches released as version 9.6.0-alpha.41 and 8.6.52