216.73.217.15

CVE-2026-27804

· Published 26/02/2026 00:16 · Modified 27/02/2026 14:06

Labels: CVE-2026-27804 2026-02-26CVE-2026-27804CWE-327[email protected]

Essential information

Published
26/02/2026 00:16
Modified
27/02/2026 14:06
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authentication token with `alg: "none"` to log in as any user linked to a Google account, without knowing their credentials. All deployments with Google authentication enabled are affected. The fix in versions 8.6.3 and 9.1.1-alpha.4 hardcodes the expected `RS256` algorithm instead of trusting the JWT header, and replaces the Google adapter's custom key fetcher with `jwks-rsa` which rejects unknown key IDs. As a workaround, dsable Google authentication until upgrading is possible.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
parse / parse server cpe:2.3:a:parse:parse_server:<8.6.3:*:*:*:*:*:*:*
parse / parse server cpe:2.3:a:parse:parse_server:<9.1.1-alpha.4:*:*:*:*:*:*:*

References