CVE-2026-33627
published 2026-03-24CVE-2026-33627: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.38%
29.6th percentile
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an authenticated user calling GET /users/me receives unsanitized auth data, including sensitive credentials such as MFA TOTP secrets and recovery codes. The endpoint internally uses master-level authentication for the session query, and the master context leaks through to the user data, bypassing auth adapter sanitization. An attacker who obtains a user's session token can extract MFA secrets to generate valid TOTP codes indefinitely. This issue has been patched in versions 8.6.61 and 9.6.0-alpha.55.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| parse-community | parse-server | < 8.6.61 | 8.6.61 |
| parse-community | parse-server | — | — |
| parse-community | parse-server | >= 0 < 8.6.61 | 8.6.61 |
| parse-community | parse-server | >= 9.0.0 < 9.6.0-alpha.55 | 9.6.0-alpha.55 |
| parseplatform | parse-server | < 8.6.61 | 8.6.61 |
| parseplatform | parse-server | — | — |
| parseplatform | parse-server | >= 9.0.0 < 9.6.0 | 9.6.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Parse Server exposes auth data via /users/me endpoint
ghsa·2026-03-24
CVE-2026-33627 [HIGH] CWE-200 Parse Server exposes auth data via /users/me endpoint
Parse Server exposes auth data via /users/me endpoint
### Impact
An authenticated user calling `GET /users/me` receives unsanitized auth data, including sensitive credentials such as MFA TOTP secrets and recovery codes. The endpoint internally uses master-level authentication for the session query, and the master context leaks through to the user data, bypassing auth adapter sanitization. An attacker who obtains a user's session token can extract MFA secrets to generate valid TOTP codes indefinitely.
### Patches
The `/users/me` endpoint now queries the session and user data separately, using the caller's authentication context for the user query so that all security layers apply correctly.
### Workarounds
There is no known workaround.
OSV
Parse Server exposes auth data via /users/me endpoint
osv·2026-03-24
CVE-2026-33627 [HIGH] Parse Server exposes auth data via /users/me endpoint
Parse Server exposes auth data via /users/me endpoint
### Impact
An authenticated user calling `GET /users/me` receives unsanitized auth data, including sensitive credentials such as MFA TOTP secrets and recovery codes. The endpoint internally uses master-level authentication for the session query, and the master context leaks through to the user data, bypassing auth adapter sanitization. An attacker who obtains a user's session token can extract MFA secrets to generate valid TOTP codes indefinitely.
### Patches
The `/users/me` endpoint now queries the session and user data separately, using the caller's authentication context for the user query so that all security layers apply correctly.
### Workarounds
There is no known workaround.
No detection rules found.
No public exploits indexed.
https://github.com/parse-community/parse-server/commit/5b8998e6866bcf75be7b5bb625e27d23bfaf912chttps://github.com/parse-community/parse-server/commit/875cf10ac979bd60f70e7a0c534e2bc194d6982fhttps://github.com/parse-community/parse-server/pull/10278https://github.com/parse-community/parse-server/pull/10279https://github.com/parse-community/parse-server/security/advisories/GHSA-37mj-c2wf-cx96
2026-03-24
Published