CVE-2026-33323 Details
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return distinguishable responses depending on whether the provided username exists and has an unverified email. This allows an unauthenticated attacker to enumerate valid usernames by observing different redirect targets. The existing emailVerifySuccessOnInvalidEmail configuration option, which is enabled by default and protects the API route against this, did not apply to these routes. This issue has been patched in versions 8.6.51 and 9.6.0-alpha.40.
A vulnerability in Parse Server's Pages and legacy PublicAPI routes for resending email verification links allows for username enumeration. Prior to versions 8.6.51 and 9.6.0-alpha.40, these routes returned different responses based on the existence of the username and the verification status of the email. This discrepancy could be exploited by an unauthenticated attacker to identify valid usernames. The issue arose because the default configuration option 'emailVerifySuccessOnInvalidEmail', which protects against such enumeration on the API route, did not apply to the affected routes.
Users can upgrade to Parse Server versions 8.6.51 or 9.6.0-alpha.40, both of which have been patched to prevent this vulnerability by ensuring the email verification resend routes respect the 'emailVerifySuccessOnInvalidEmail' configuration option.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-204 | Observable Response Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| parseplatform parse-server | < 8.6.51 >= 9.0.0, < 9.6.0 9.6.0 alpha1 9.6.0 alpha10 9.6.0 alpha11 9.6.0 alpha12 9.6.0 alpha13 9.6.0 alpha14 9.6.0 alpha15 9.6.0 alpha16 9.6.0 alpha17 9.6.0 alpha18 9.6.0 alpha19 9.6.0 alpha2 9.6.0 alpha20 9.6.0 alpha21 9.6.0 alpha22 9.6.0 alpha23 9.6.0 alpha24 9.6.0 alpha25 9.6.0 alpha26 9.6.0 alpha27 9.6.0 alpha28 9.6.0 alpha29 9.6.0 alpha3 9.6.0 alpha30 9.6.0 alpha31 9.6.0 alpha32 9.6.0 alpha33 9.6.0 alpha34 9.6.0 alpha35 9.6.0 alpha36 9.6.0 alpha37 9.6.0 alpha38 9.6.0 alpha39 9.6.0 alpha4 9.6.0 alpha5 9.6.0 alpha6 9.6.0 alpha7 9.6.0 alpha8 9.6.0 alpha9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | Initial Analysis | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |