Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication adapters use JWT verification to validate identity tokens. When the adapter's audience configuration option is not set (clientId for Google/Apple, appIds for Facebook), JWT verification silently skips audience claim validation. This allows an attacker to use a validly signed JWT issued for a different application to authenticate as any user on the target Parse Server. This issue has been patched in versions 8.6.10 and 9.5.0-alpha.11.

INFO

Published Date :

2026-03-07T16:18:47.786Z

Last Modified :

2026-03-09T18:25:24.090Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-30863 vulnerability.

Vendors Products
Parse Community
  • Parse Server
Parseplatform
  • Parse-server
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-30863.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact