CVE-2026-33409 Details
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as any user who has linked a third-party authentication provider, without knowing the user's credentials. The attacker only needs to know the user's provider ID to gain full access to their account, including a valid session token. This affects Parse Server deployments where the server option allowExpiredAuthDataToken is set to true. The default value is false. This issue has been patched in versions 8.6.52 and 9.6.0-alpha.41.
An authentication bypass vulnerability has been identified in Parse Server, allowing attackers to log in as any user linked to a third-party authentication provider, without needing the user's credentials. This vulnerability exists in Parse Server versions 9.0.0 prior to 9.6.0-alpha.41 and versions prior to 8.6.52. The issue arises when the server option 'allowExpiredAuthDataToken' is set to true, which is not the default setting. Exploitation requires knowledge of the user's provider ID, granting access to the user's account and a valid session token.
Parse Server versions 8.6.52 and 9.6.0-alpha.41 have patched this vulnerability. Users should update to these versions. Additionally, the 'allowExpiredAuthDataToken' option can be set to false or removed from the server configuration to prevent this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| parseplatform parse-server | < 8.6.52 >= 9.0.0, < 9.6.0 9.6.0 alpha1 9.6.0 alpha10 9.6.0 alpha11 9.6.0 alpha12 9.6.0 alpha13 9.6.0 alpha14 9.6.0 alpha15 9.6.0 alpha16 9.6.0 alpha17 9.6.0 alpha18 9.6.0 alpha19 9.6.0 alpha2 9.6.0 alpha20 9.6.0 alpha21 9.6.0 alpha22 9.6.0 alpha23 9.6.0 alpha24 9.6.0 alpha25 9.6.0 alpha26 9.6.0 alpha27 9.6.0 alpha28 9.6.0 alpha29 9.6.0 alpha3 9.6.0 alpha30 9.6.0 alpha31 9.6.0 alpha32 9.6.0 alpha33 9.6.0 alpha34 9.6.0 alpha35 9.6.0 alpha36 9.6.0 alpha37 9.6.0 alpha38 9.6.0 alpha39 9.6.0 alpha4 9.6.0 alpha40 9.6.0 alpha5 9.6.0 alpha6 9.6.0 alpha7 9.6.0 alpha8 9.6.0 alpha9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | Initial Analysis | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |