CVE-2026-32269 impacts Parse Server deployments that use the OAuth2 authentication adapter with `appidField` and `appIds` configured. The vulnerability involves incorrect app ID validation, where a malformed value is sent to the token introspection endpoint instead of the user's actual access token. This medium-severity flaw (CVSS 6.5) is network-exploitable with low complexity, potentially leading to a denial of service for OAuth2 logins or allowing authentication from disallowed app contexts. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, and community discussion remains minimal. Affected systems should upgrade to Parse Server 9.6.0-alpha.13 or 8.6.39 to remediate.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.2, < 8.6.39CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
>= 9.0.0, < 9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha1:*:*:*:node.js:*:* | ||
9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha10:*:*:*:node.js:*:* | ||
9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha11:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.