Protection Mechanism Failure in Parse Server - CVE-2026-30938

 

Protection Mechanism Failure in Parse Server - CVE-2026-30938

Published: April 6, 2026


Vulnerability identifier: #VU124980
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-30938
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass a keyword denylist protection.

The vulnerability exists due to protection mechanism failure in the requestKeywordDenylist keyword scanner when processing request payloads containing a nested object or array before a prohibited keyword. A remote attacker can send a specially crafted request payload to bypass a keyword denylist protection.

The requestKeywordDenylist security control is enabled by default, and custom denylist entries configured by the developer are affected as well.


Affected software

Parse Server

How to mitigate CVE-2026-30938

Install security update from vendor's website.

Parse Server - addressed in versions 8.6.12, 9.5.1 alpha.1

External References

Related Security Bulletins