216.73.217.22

CVE-2026-31875

· Published 11/03/2026 18:16 · Modified 12/03/2026 21:08

Labels: CVE-2026-31875 2026-03-11CVE-2026-31875CWE-672[email protected]

Essential information

Published
11/03/2026 18:16
Modified
12/03/2026 21:08
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generates two single-use recovery codes. These codes are intended as a fallback when the user cannot provide a TOTP token. However, recovery codes are not consumed after use, allowing the same recovery code to be used an unlimited number of times. This defeats the single-use design of recovery codes and weakens the security of MFA-protected accounts. An attacker who obtains a single recovery code can repeatedly authenticate as the affected user without the code ever being invalidated. This vulnerability is fixed in 9.6.0-alpha.7 and 8.6.33.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
parse / parse server cpe:2.3:a:parse:parse_server:<9.6.0-alpha.7:*:*:*:*:*:*:*
parse / parse server cpe:2.3:a:parse:parse_server:<8.6.33:*:*:*:*:*:*:*

References