PT-2026-99555 · Unknown · Parse Server
CVSS v4.0
7.4
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Parse Server versions 9.0.0 through 9.10.1-alpha.9
Parse Server versions 8.0.2 through 8.6.90
Description
Code-based authentication adapters for GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, and Weibo fail to verify the client authorization code with the external provider when authentication data is submitted with a username and password at the login endpoint. This allows an authenticated user with low privileges to link an unverified provider identity to their account without contacting the provider, enabling the spoofing of external identities. Additionally, an attacker can pre-hijack accounts by claiming a provider ID of a victim who has not yet linked that provider, causing the victim's subsequent legitimate sign-in to resolve to the attacker's account. This issue only impacts deployments that configure the affected code-based authentication adapters.
Recommendations
Update Parse Server to version 9.10.1-alpha.10 or later.
Update Parse Server to version 8.6.91 or later.
As a temporary workaround, disable the affected code-based authentication adapters.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parse Server