CVE-2026-101042
published 2026-09-27CVE-2026-101042: Parse Server is an open-source backend server. In versions >= 9.0.0 = 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games…
PriorityP343medium6.4CVSS 3.1
AVNACHPRLUIRSUCHIHAN
EPSS
0.21%
10.6th percentile
Parse Server is an open-source backend server. In versions >= 9.0.0 = 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup and on provider linking, but not when authentication data is supplied together with a username and password on the login endpoint. As a result, a low-privileged authenticated user can attach an arbitrary, unverified provider identity to their own account without the provider ever being contacted, spoofing an external identity toward application logic that trusts the linked provider ID. An attacker can also pre-hijack accounts: by claiming the provider ID of a victim who has not yet linked that provider, the victim's later legitimate sign-in with that provider resolves to the attacker's account. Only deployments configuring one of the affected code-based auth adapters are impacted. Versions 9.10.1-alpha.10 and 8.6.91 fix the issue by running the adapter's credential verification on the login and challenge endpoints and rejecting a provider identity already linked to another user. As a workaround, disable the affected code-based auth adapters.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| parse-community | parse-server | >= 8.0.2 < 8.6.91 | 8.6.91 |
| parse-community | parse-server | >= 9.0.0 < 9.10.1-alpha.10 | 9.10.1-alpha.10 |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Parse Community Parse Server 8.6.90/9.10.1-alpha.9 Login Endpoint improper authorization
vuldb·2026-09-27·CVSS 6.4
CVE-2026-101042 [MEDIUM] Parse Community Parse Server 8.6.90/9.10.1-alpha.9 Login Endpoint improper authorization
A vulnerability was found in Parse Community Parse Server 8.6.90/9.10.1-alpha.9 and classified as problematic. This affects an unknown part of the component Login Endpoint. Such manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-101042. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
Parse Server is an open-source backend server.
ghsa_unreviewed·2026-09-27
CVE-2026-101042 [HIGH] CWE-287 Parse Server is an open-source backend server.
Parse Server is an open-source backend server. In versions >= 9.0.0 = 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup and on provider linking, but not when authentication data is supplied together with a username and password on the login endpoint. As a result, a low-privileged authenticated user can attach an arbitrary, unverified provider identity to their own account without the provider ever being contacted, spoofing an external identity toward application logic that trusts the linked provider ID. An attacker can also pre-hijack accounts: by claiming the provider ID of a victim who has not yet linked that provid
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-27
Published