SB2026040762 - Improper Neutralization of Special Elements in Data Query Logic in Parse Server



SB2026040762 - Improper Neutralization of Special Elements in Data Query Logic in Parse Server

Published: April 7, 2026

Security Bulletin ID SB2026040762
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-30941)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements in data query logic in the password reset and email verification resend endpoints when processing the token field in requests. A remote attacker can send a specially crafted token value with MongoDB query operators to disclose sensitive information.

When emailVerifyTokenReuseIfValid is configured, the extracted email verification token can be used to verify a user's email address without inbox access.


Remediation

Install update from vendor's website.