SB2026091513 - Improper Authentication in Parse Server
Published: September 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Authentication (CVE-ID: N/A)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to spoof an external identity and pre-hijack accounts.
The vulnerability exists due to improper authentication in Parse Server's code-based authentication adapters when authentication data is supplied with a username and password to the login endpoint. A remote user can attach an arbitrary unverified provider identity to their own account to spoof an external identity and pre-hijack accounts.
Only deployments configured with an affected code-based authentication adapter are vulnerable.
Remediation
Install update from vendor's website.