CVE-2026-30863
CRITICALParse Server <8.6.10/9.5.0-alpha.11 - Auth Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-30863. PoCs published by Worthes.
AI-analyzed exploit summary The repository lacks actual exploit code and instead directs users to an external download link, which is a common tactic for distributing malware or fake exploits. The README provides technical details about the vulnerability but does not include functional exploit code.
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication adapters use JWT verification to validate identity tokens. When the adapter's audience configuration option is not set (clientId for Google/Apple, appIds for Facebook), JWT verification silently skips audience claim validation. This allows an attacker to use a validly signed JWT issued for a different application to authenticate as any user on the target Parse Server. This issue has been patched in versions 8.6.10 and 9.5.0-alpha.11.
Exploits (1)
The repository lacks actual exploit code and instead directs users to an external download link, which is a common tactic for distributing malware or fake exploits. The README provides technical details about the vulnerability but does not include functional exploit code.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H