CVE-2026-34215

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP secrets, recovery codes, and OAuth access tokens. An attacker who knows a user's password can extract the MFA secret to generate valid MFA codes, defeating multi-factor authentication protection. This issue has been patched in versions 8.6.63 and 9.7.0-alpha.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha2:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha3:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha4:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha5:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha6:*:*:*:node.js:*:*

History

01 Apr 2026, 17:12

Type Values Removed Values Added
First Time Parseplatform
Parseplatform parse-server
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha4:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha3:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha6:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha2:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha5:*:*:*:node.js:*:*
References () https://github.com/parse-community/parse-server/commit/770be8647424d92f5425c41fa81065ffbbb171ed - () https://github.com/parse-community/parse-server/commit/770be8647424d92f5425c41fa81065ffbbb171ed - Patch
References () https://github.com/parse-community/parse-server/commit/a1d4e7b12a12f16d3870dbee582a36765858e94c - () https://github.com/parse-community/parse-server/commit/a1d4e7b12a12f16d3870dbee582a36765858e94c - Patch
References () https://github.com/parse-community/parse-server/pull/10323 - () https://github.com/parse-community/parse-server/pull/10323 - Issue Tracking, Patch
References () https://github.com/parse-community/parse-server/pull/10324 - () https://github.com/parse-community/parse-server/pull/10324 - Issue Tracking, Patch
References () https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258 - () https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258 - Patch, Vendor Advisory

31 Mar 2026, 22:16

Type Values Removed Values Added
References
  • {'url': 'https://github.com/parse-community/parse-server/commit/5b8998e6866bcf75be7b5bb625e27d23bfaf912c', 'source': 'security-advisories@github.com'}
  • {'url': 'https://github.com/parse-community/parse-server/commit/875cf10ac979bd60f70e7a0c534e2bc194d6982f', 'source': 'security-advisories@github.com'}
  • {'url': 'https://github.com/parse-community/parse-server/pull/10278', 'source': 'security-advisories@github.com'}
  • {'url': 'https://github.com/parse-community/parse-server/pull/10279', 'source': 'security-advisories@github.com'}
  • () https://github.com/parse-community/parse-server/commit/770be8647424d92f5425c41fa81065ffbbb171ed -
  • () https://github.com/parse-community/parse-server/commit/a1d4e7b12a12f16d3870dbee582a36765858e94c -
  • () https://github.com/parse-community/parse-server/pull/10323 -
  • () https://github.com/parse-community/parse-server/pull/10324 -

31 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 20:16

Updated : 2026-04-03 17:16


NVD link : CVE-2026-34215

Mitre link : CVE-2026-34215

CVE.ORG link : CVE-2026-34215


JSON object : View

Products Affected

parseplatform

  • parse-server
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo