S4E just found a high top 10 tcp port service scan
critical·Misconfiguration·Updated Aug 30, 2026

CVE-2026-30965 Scanner

CVE-2026-30965 Scanner - Information Disclosure vulnerability in Parse Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-30965
9.9
CVSScritical
Exploitable remotely over the internet · no authentication required.

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiting the redirectClassNameForKey query parameter. Exfiltrated session tokens can be used to take over user accounts. The vulnerability requires the attacker to be able to create or update an object with a new relation field, which depends on the Class-Level Permissions of at least one class. This vulnerability is fixed in 9.5.2-alpha.8 and 8.6.21.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
parse-serverby parse-community
>= 9.0.0 < 9.5.2-alpha.8
Updated Aug 21, 2026View on NVD →
Detail

Parse Server is a widely used open-source backend framework that provides developers with features like data storage, user authentication, and real-time notifications. Deployed across numerous applications, it serves developers who aim to focus on the front-end by offloading backend complexities. It's prominently used in environments ranging from small personal projects to large enterprise applications, particularly valuing its scalability and flexibility in rapid application development. By integrating with various frontend platforms, Parse Server streamlines development workflows, especially with features for user session management and data relations. Companies and developers often choose it for its comprehensive API capabilities and ease of use, ensuring robust application function without dealing with low-level backend complications.

This information disclosure vulnerability in Parse Server arises from improper handling of the `redirectClassNameForKey` query parameter. It enables both authenticated and unauthenticated attackers to exfiltrate session tokens. The vulnerability exploits the application's access control shortcomings, specifically concerning the permissions granted for object creation or updates involving new relation fields. Its critical nature stems from the potential unauthorized access and control over user accounts if successfully exploited. This issue is severe because it bypasses typical authentication mechanisms, leading directly to unauthorized data access and manipulation.

Technically, the vulnerability allows attackers to manipulate requests enabling them to access session tokens. The specific vulnerability endpoint involves manipulating a request containing relation operations against the Parse Server's endpoint designed for managing objects. A vulnerability in how 'Class-Level Permissions' are managed regarding the API's query parameters contributes to this flaw. Attackers require minimal prior access, such as object creation permissions, to exploit and subsequently access unauthorized session information. Furthermore, this involves the API handling, especially the ability to inject relations through a crafted HTTP request leading to unauthorized information exposure.

Malicious exploitation can lead to severe consequences such as account takeover and unauthorized access to sensitive information within applications leveraging Parse Server. Compromised session tokens could allow attackers to impersonate users, perform unauthorized actions, or exfiltrate private user data. Such escalations can undermine user trust, disrupt services, cause unauthorized data loss or manipulation, and potentially breach regulatory compliances for securing user data. Organizations using affected versions may face significant security, reputational, and financial risks due to the misuse of exposed session tokens.

REFERENCES

Solution Advice
  • Update Parse Server to version 9.5.2-alpha.8 or 8.6.21 or later.
  • Ensure that Class-Level Permissions are correctly configured to prevent unauthorized object creations or updates.
  • Review and enhance access control mechanisms to prevent improper access or exfiltration of sensitive tokens.
  • Implement additional logs and monitoring to detect unusual activities related to session token accesses.
  • Conduct regular security audits and inspections to identify and mitigate potential vulnerabilities proactively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.