Record summary

CVE-2026-30965 has a selected CVSS score of 9.9 (critical); EIP currently links 1 Nuclei template.

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiting the redirectClassNameForKey query parameter. Exfiltrated session tokens can be used to take over user accounts. The vulnerability requires the attacker to be able to create or update an object with a new relation field, which depends on the Class-Level Permissions of at least one class. This vulnerability is fixed in 9.5.2-alpha.8 and 8.6.21.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List>= 9.0.0 < 9.5.2-alpha.8affected
< 8.6.21affected
GitHub Advisory9.0.0-alpha.1 to < 9.5.2-alpha.8 · Fixed in 9.5.2-alpha.8affected
Before 8.6.21 · Fixed in 8.6.21affected

Nuclei templates

1
ProjectDiscoveryCRITICALParse Server < 8.6.21 / 9.x < 9.5.2 - Session Token ExfiltrationCVSS 9.9

Parse Server < 8.6.21 / 9.x < 9.5.2 contains an information disclosure vulnerability caused by improper handling of the redirectClassNameForKey query parameter, letting authenticated or unauthenticated attackers exfiltrate session tokens, exploit requires ability to create or update an object with a new relation field depending on Class-Level Permissions.

Impact

Attackers can exfiltrate session tokens and take over user accounts, leading to account compromise.

Remediation

Update to version 9.5.2-alpha.8 or 8.6.21 or later.

WeaknessesCWE-863
Authorsstr4k3r, 0x_Akoko
Template tagscvecve2026parseparse-serversession-hijackauth-bypass
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Shodan: "X-Parse-Application-Id" OR http.html:"parseServerVersion"
FOFA: body="parseServerVersion" || header="X-Parse-Application-Id"

Source: ProjectDiscovery

References

5