CVE-2026-34532 details a critical access control bypass vulnerability affecting Parse Server versions prior to 8.6.67 and 9.7.0-alpha.11. This flaw allows unauthenticated attackers to invoke protected Cloud Functions by appending "prototype.constructor" to the function name in the URL, thereby bypassing validator access controls. Rated 9.1 CRITICAL on the CVSS scale, it presents a low-complexity network attack vector with high potential impact on confidentiality and integrity. Currently, there is no evidence of active exploitation or public exploit code available, though the vulnerability has received limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.67CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
>= 9.0.0, < 9.7.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
9.7.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha1:*:*:*:node.js:*:* | ||
9.7.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha10:*:*:*:node.js:*:* | ||
9.7.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha2:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.