PT-2026-99555 · Unknown · Parse Server

·

CVE-2026-101042

·

Published

2026-09-27

·

Updated

2026-10-05

CVSS v4.0

7.4

High

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions 9.0.0 through 9.10.1-alpha.9 Parse Server versions 8.0.2 through 8.6.90
Description Code-based authentication adapters for GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, and Weibo fail to verify the client authorization code with the external provider when authentication data is submitted with a username and password at the login endpoint. This allows an authenticated user with low privileges to link an unverified provider identity to their account without contacting the provider, enabling the spoofing of external identities. Additionally, an attacker can pre-hijack accounts by claiming a provider ID of a victim who has not yet linked that provider, causing the victim's subsequent legitimate sign-in to resolve to the attacker's account. This issue only impacts deployments that configure the affected code-based authentication adapters.
Recommendations Update Parse Server to version 9.10.1-alpha.10 or later. Update Parse Server to version 8.6.91 or later. As a temporary workaround, disable the affected code-based authentication adapters.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-101042
CVE-2026-101042
GHSA-MR43-W6C2-MVJQ

Affected Products

Parse Server