CVE Explorer
CVE-2026-32242
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations. Under concurrent authentication requests for different OAuth2 providers, one provider's token validation may execute using another provider's configuration, potentially allowing a token that should be rejected by one pro
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"parse-server","vendor":"parse-community","versions":[{"status":"affected","version":">= 9.0.0 < 9.6.0-alpha.11"},{"status":"affected","version":"< 8.6.37"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b7657290fae8834b6489e56e6d9f77f722c19b5c71058d33c3fd949937596d79 · sha256:55c2b7f4d88d11d6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":9.1,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b7657290fae8834b6489e56e6d9f77f722c19b5c71058d33c3fd949937596d79 · sha256:55c2b7f4d88d11d6… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-362","description":"CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b7657290fae8834b6489e56e6d9f77f722c19b5c71058d33c3fd949937596d79 · sha256:55c2b7f4d88d11d6… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/parse-community/parse-server/releases/tag/8.6.37","tags":["x_refsource_MISC"],"url":"https://github.com/parse-community/parse-server/releases/tag/8.6.37"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b7657290fae8834b6489e56e6d9f77f722c19b5c71058d33c3fd949937596d79 · sha256:55c2b7f4d88d11d6… · /containers/cna/references/1
{"name":"https://github.com/parse-community/parse-server/releases/tag/9.6.0-alpha.11","tags":["x_refsource_MISC"],"url":"https://github.com/parse-community/parse-server/releases/tag/9.6.0-alpha.11"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b7657290fae8834b6489e56e6d9f77f722c19b5c71058d33c3fd949937596d79 · sha256:55c2b7f4d88d11d6… · /containers/cna/references/2
{"name":"https://github.com/parse-community/parse-server/security/advisories/GHSA-2cjm-2gwv-m892","tags":["x_refsource_CONFIRM"],"url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-2cjm-2gwv-m892"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b7657290fae8834b6489e56e6d9f77f722c19b5c71058d33c3fd949937596d79 · sha256:55c2b7f4d88d11d6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.