CVE-2026-33527
Estado: AnalizadaMedia (5.3)—
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.57 and 9.6.0-alpha.48, an authenticated user can overwrite server-generated session fields such as expiresAt and createdWith when updating their own session via the REST API. This allows bypassing the server's configured session lifetime policy, making a session effectively permanent. This issue has been patched in versions 8.6.57 and 9.6.0-alpha.48.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
Referencias
- https://github.com/parse-community/parse-server/commit/26b628c8fb3cc79ea955374769eebcff6f8a8a73
- https://github.com/parse-community/parse-server/commit/ea68fc0b22a6056c9675149469ff57817f7cf984
- https://github.com/parse-community/parse-server/pull/10263
- https://github.com/parse-community/parse-server/pull/10264
- https://github.com/parse-community/parse-server/security/advisories/GHSA-jc39-686j-wp6q
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-33527",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-33527",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-24T20:36:32.237013Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 5.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "parse-community",
"product": "parse-server",
"versions": [
{
"status": "affected",
"version": "< 8.6.57"
},
{
"status": "affected",
"version": ">= 9.0.0, < 9.6.0-alpha.48"
}
]
}
]
}
],
"published": "2026-03-24T19:16:54.510",
"references": [
{
"url": "https://github.com/parse-community/parse-server/commit/26b628c8fb3cc79ea955374769eebcff6f8a8a73",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/parse-community/parse-server/commit/ea68fc0b22a6056c9675149469ff57817f7cf984",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/parse-community/parse-server/pull/10263",
"tags": [
"Issue Tracking"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/parse-community/parse-server/pull/10264",
"tags": [
"Issue Tracking"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-jc39-686j-wp6q",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.57 and 9.6.0-alpha.48, an authenticated user can overwrite server-generated session fields such as expiresAt and createdWith when updating their own session via the REST API. This allows bypassing the server's configured session lifetime policy, making a session effectively permanent. This issue has been patched in versions 8.6.57 and 9.6.0-alpha.48."
},
{
"lang": "es",
"value": "Parse Server es un backend de código abierto que puede ser desplegado en cualquier infraestructura que pueda ejecutar Node.js. Antes de las versiones 8.6.57 y 9.6.0-alpha.48, un usuario autenticado puede sobrescribir campos de sesión generados por el servidor, como expiresAt y createdWith, al actualizar su propia sesión a través de la API REST. Esto permite eludir la política de vida útil de la sesión configurada del servidor, haciendo que una sesión sea efectivamente permanente. Este problema ha sido parcheado en las versiones 8.6.57 y 9.6.0-alpha.48."
}
],
"lastModified": "2026-06-17T10:37:39.310",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "63687515-718A-42DF-85D2-3AD86345A111",
"versionEndExcluding": "8.6.57"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "1BAC01F8-0899-482C-8D91-64671BF2859A",
"versionEndExcluding": "9.6.0",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "BBED261F-CA1B-44BC-9C3A-37378590EFEE"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha10:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "418338C9-6AEC-492C-ACA4-9B3C0AAE149C"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha11:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "808B6482-BF8E-407D-8462-E757657CC323"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha12:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B84C28F8-AADE-41BB-A0EF-B701AB57DC3A"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha13:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "7567BB81-7837-4265-B792-6A9B73CECF93"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha14:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "0035C6F1-21B9-42D1-BE29-690905F3558C"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha15:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "623FB30A-0693-4449-80FA-16D36B1BE66C"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha16:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9B420167-CD3E-45A7-AD9A-0F83AEC634BA"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha17:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "030A8626-DBBD-4BF2-B362-79B44FB1204D"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha18:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "D38CFCC3-2AA9-4C8E-9064-FE97E6E8C45C"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha19:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "65BB78F2-3A1A-4CD1-B8A8-4AB043B5CA50"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "EDC98AF7-8620-4A25-9BE5-623672599677"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha20:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "23E28E0F-9379-4628-B9DC-8C94A45902CF"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha21:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "6631BE51-74FB-40C0-9E91-0EDF2DCADD7A"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha22:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8B0E4254-14A3-4EB6-9E98-CF45EB08B17F"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha23:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "0FF63FDE-75F5-44B6-A958-CF653D84D3B4"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha24:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "252B812D-A162-41C1-91CD-08D0CBAC5C46"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha25:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "421691EA-F55A-4738-8ABD-74B53B6DF155"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha26:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "5E7FAB59-142E-4191-9A6F-0744D810CD81"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha27:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B010F310-05A1-48AE-B002-8F4C7FA62EB3"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha28:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "4D3B2C32-16D8-415B-A49F-060ECE8F0F33"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha29:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "43BE83C2-C756-4A5A-A340-B7D1FB52078D"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "DF340605-8CC8-4543-9F5D-E8602D258CED"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha30:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "702EBB22-3E9F-4CBE-B855-2E3642C530B1"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha31:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "7C17AD66-684F-4662-AF16-838FF05F47D5"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha32:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "13C25963-CAE7-49AA-A941-254DCE289E35"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha33:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B6BF0C2F-DD2B-4864-961F-CA808EF22633"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha34:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8FBB21E9-CB73-4CB1-841A-D1C08167DB51"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha35:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "4CD55F0B-D854-43D4-A0F5-F83386DB24C9"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha36:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "1097E8DF-3D0E-47C6-882D-E37B22119538"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha37:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8C60F121-1C0B-4EB5-87EF-F1BED070C13B"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha38:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "04D8514D-CC66-4E6B-90C8-6108F0DAA661"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha39:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "4BB65A73-7BB7-42E4-97A3-4D6305172E05"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A052DFCA-EDCC-43D7-82C7-E5311F6F7687"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha40:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "192A78FB-E141-4F14-8C4A-20A4118B01C9"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha41:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "CA4FEA42-4240-42B1-A5C2-6F74CBBACB92"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha42:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "7192B894-2616-4852-850B-39CF6FCAC4F1"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha43:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "3323535E-C323-4FD9-81E9-8F7A045EDD59"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha44:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "20A0CF2D-C8C0-4972-8F2B-02B67C171CA2"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha45:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "EDC9ECE2-303E-429F-8E1B-EC6C6C575642"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha46:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A8914A97-5BCA-44ED-8767-1C4B5029CA2E"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha47:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "D1BA3306-9F5B-4F9D-B472-D04E9018667E"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha5:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "12B11714-B961-4330-B241-FC5AF94FDBE8"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha6:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "37A7C42B-4986-4BB6-BB27-0324A9AA1CFF"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha7:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "C793834B-64B4-4DE9-BD7D-79B52C30C34E"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha8:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "7AD455C8-88BE-4A0A-B33D-3A7811FFB753"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha9:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "26C475A2-997C-4C3A-8CB6-04AB3534BBC3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}