CVE-2026-34224Medium· 4.4▾ SunlitParse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery code or SMS one-time password can create multiple authenticated sessions by sending concurrent login requests via the authData login endpoint. This defeats the single-use guarantee of MFA recovery codes and SMS one-time passwords, allowing session persistence even after the legitimate user revokes detected sessions. This issue has been patched in versions 8.6.64 and 9.7.0-alpha.8.
parse-server < 8.6.64parse-server >= 9.0.0, < 9.7.0parse-server = 9.7.0Upgrade past the affected range:
parse-server 9.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23950High· 8.8node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3
CVE-2026-87806High· 7.4Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter
CVE-2026-34373High· 8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34363Medium· 5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34595Medium· 4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34574Medium· 5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js