SB2026040762 - Improper Neutralization of Special Elements in Data Query Logic in Parse Server
Published: April 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-30941)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements in data query logic in the password reset and email verification resend endpoints when processing the token field in requests. A remote attacker can send a specially crafted token value with MongoDB query operators to disclose sensitive information.
When emailVerifyTokenReuseIfValid is configured, the extracted email verification token can be used to verify a user's email address without inbox access.
Remediation
Install update from vendor's website.