#VU124991 Improper Authentication in Parse Server - CVE-2026-30949
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote user to authenticate as any user.
The vulnerability exists due to improper authentication in the Keycloak authentication adapter when validating Keycloak access tokens. A remote user can present a valid access token issued for a different client application in the same Keycloak realm to authenticate as any user.
Only deployments that use the Keycloak authentication adapter with a Keycloak realm containing multiple client applications are vulnerable.