CVE-2026-34532
Parse Server, an open‑source backend for Node.js, had a flaw that let attackers bypass Cloud Function access controls by appending a special string to the function name. The vulnerability was fixed in version 8.6.67 and 9.7.0‑alpha.11. Users should upgrade to a patched release to protect their functions.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Parse Server (open‑source backend) versions before 8.6.67 and 9.7.0‑alpha.11. Developers deploying Parse Server on any infrastructure that can run Node.js.
Real-world impact
An attacker could call protected Cloud Functions without authentication, potentially exposing data or executing arbitrary code.
Why this severity
The CVSS score of 9.1 reflects the high impact of bypassing authentication (high confidentiality impact) combined with low attack complexity and no user interaction, making it a critical vulnerability.
What to do about it
- 01Upgrade Parse Server to version 8.6.67 or later, or to 9.7.0‑alpha.11 or later.
- 02Restart the Parse Server service to apply the update.
NVD-referenced vendor advisory
Timeline
- Mar 31, 2026 · Mar 31, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/parse-community/parse-serve…patch
- github.com/parse-community/parse-serve…patch
- github.com/parse-community/parse-serve…issue trackingpatch
- github.com/parse-community/parse-serve…issue trackingpatch
- github.com/parse-community/parse-serve…mitigationpatchvendor advisory