CVE-2026-34784 is a high-severity vulnerability in Parse Server versions prior to 8.6.71 and 9.7.1-alpha.1, where HTTP Range requests can bypass the afterFind(Parse.File) trigger and its validators on streaming storage adapters, leading to unauthorized file downloads. With a CVSS score of 8.2, this flaw has a network attack vector and low complexity, allowing unauthenticated attackers to access protected files. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.71CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
>= 9.0.0, < 9.7.1CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.