SB2026040783 - Improper Authentication in Parse Server



SB2026040783 - Improper Authentication in Parse Server

Published: April 7, 2026

Security Bulletin ID SB2026040783
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2026-30863)

The vulnerability allows a remote attacker to authenticate as any user on the target Parse Server.

The vulnerability exists due to improper authentication in the Google, Apple, and Facebook authentication adapters when verifying identity tokens without audience claim validation. A remote attacker can present a validly signed JWT issued for a different application to authenticate as any user on the target Parse Server.

For Google and Apple, exploitation is possible when the server does not configure clientId. For Facebook Limited Login, the JWT verification path does not validate appIds as the audience.


Remediation

Install update from vendor's website.