PT-2026-24427 · Unknown+2 · Parse Server+2

·

CVE-2026-30949

·

Published

2026-03-10

·

Updated

2026-03-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.5.2-alpha.5 Parse Server versions prior to 8.6.18
Description Parse Server, an open source backend deployable on Node.js infrastructures, contains a flaw in its Keycloak authentication adapter. Specifically, the adapter fails to validate the azp (authorized party) claim within Keycloak access tokens against the expected client-id. This allows a valid access token from a different client application within the same Keycloak realm to be used for authentication, potentially leading to cross-application account takeover. Deployments utilizing the Keycloak authentication adapter with multi-client Keycloak realms are susceptible. The issue affects all Parse Server deployments using the Keycloak authentication adapter with a Keycloak realm that has multiple client applications.
Recommendations Update to Parse Server version 9.5.2-alpha.5 or later. Update to Parse Server version 8.6.18 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-30949
CVE-2026-30949
GHSA-48MH-J4P5-7J9V

Affected Products

Keycloak
Node.Js
Parse Server