SB2026040752 - Function Call With Incorrect Order of Arguments in Parse Server



SB2026040752 - Function Call With Incorrect Order of Arguments in Parse Server

Published: April 7, 2026

Security Bulletin ID SB2026040752
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Function Call With Incorrect Order of Arguments (CVE-ID: CVE-2026-32269)

The vulnerability allows a remote attacker to bypass app ID restrictions during OAuth2 authentication.

The vulnerability exists due to function call with incorrect order of arguments in the OAuth2 authentication adapter app ID validation method when validating app IDs with configured appidField and appIds. A remote attacker can trigger OAuth2 authentication with a malformed introspection request to bypass app ID restrictions during OAuth2 authentication.

Deployments are affected only when the OAuth2 adapter is used with both appidField and appIds configured.


Remediation

Install update from vendor's website.