SB2026040754 - Race condition in Parse Server



SB2026040754 - Race condition in Parse Server

Published: April 7, 2026

Security Bulletin ID SB2026040754
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Race condition (CVE-ID: CVE-2026-32242)

The vulnerability allows a remote attacker to bypass OAuth2 token validation and gain unauthorized access.

The vulnerability exists due to a race condition in the built-in OAuth2 auth adapter when handling concurrent authentication requests for different OAuth2 providers. A remote attacker can send concurrent authentication requests to cause one provider's token validation to use another provider's configuration to bypass OAuth2 token validation and gain unauthorized access.

Only deployments that configure multiple OAuth2 providers via the oauth2: true flag are vulnerable.


Remediation

Install update from vendor's website.