Incorrect authorization in Parse Server - CVE-2026-29182

 

Incorrect authorization in Parse Server - CVE-2026-29182

Published: April 6, 2026


Vulnerability identifier: #VU124968
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-29182
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create, modify, and delete Cloud Hooks and start Cloud Jobs to exfiltrate data.

The vulnerability exists due to incorrect authorization in Cloud Hooks and Cloud Jobs endpoints when handling mutating requests authenticated with the readOnlyMasterKey. A remote privileged user can send crafted mutating requests using the readOnlyMasterKey to create, modify, and delete Cloud Hooks and start Cloud Jobs to exfiltrate data.

Only deployments that use the readOnlyMasterKey option are vulnerable.


Affected software

Parse Server

How to mitigate CVE-2026-29182

Install security update from vendor's website.

Parse Server - addressed in versions 8.6.4, 9.4.1 alpha.3

External References

Related Security Bulletins