Unknown · Parse Server · CVE-2026-101042
**Name of the Vulnerable Software and Affected Versions**
Parse Server versions 9.0.0 through 9.10.1-alpha.9
Parse Server versions 8.0.2 through 8.6.90
**Description**
Code-based authentication adapters for GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, and Weibo fail to verify the client authorization code with the external provider when authentication data is submitted with a username and password at the login endpoint. This allows an authenticated user with low privileges to link an unverified provider identity to their account without contacting the provider, enabling the spoofing of external identities. Additionally, an attacker can pre-hijack accounts by claiming a provider ID of a victim who has not yet linked that provider, causing the victim's subsequent legitimate sign-in to resolve to the attacker's account. This issue only impacts deployments that configure the affected code-based authentication adapters.
**Recommendations**
Update Parse Server to version 9.10.1-alpha.10 or later.
Update Parse Server to version 8.6.91 or later.
As a temporary workaround, disable the affected code-based authentication adapters.