CVE-2026-34532
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Function handler is declared using the function keyword and its validator is a plain object or arrow function, the trigger store traversal resolves the handler through its own prototype chain while the validator store fails to mirror this traversal, causing all access control enforcement to be skipped.
Leer descripción completaMostrar menos
This allows unauthenticated callers to invoke Cloud Functions that are meant to be protected by validators such as requireUser, requireMaster, or custom validation logic. This issue has been patched in versions 8.6.67 and 9.7.0-alpha.11.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.49%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access90 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access85 % - Impacto secundario
T1059Command and Scripting Interpreterexecution75 %
AV:N sin autenticación (PR:N) permite acceso remoto a funciones protegidas mediante bypass de validadores. Acceso no autenticado a Cloud Functions (T1078) y ejecución de código en Node.js (T1059).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-863
Referencias
- https://github.com/parse-community/parse-server/commit/4fc48cf28f22eea200d74d883505f485234a48d7
- https://github.com/parse-community/parse-server/commit/dc59e272665644083c5b7f6862d88ce1ef0b2674
- https://github.com/parse-community/parse-server/pull/10342
- https://github.com/parse-community/parse-server/pull/10343
- https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-34532",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-34532",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-03-31T17:21:00.433792Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.1,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "parse-community",
"product": "parse-server",
"versions": [
{
"status": "affected",
"version": "< 8.6.67"
},
{
"status": "affected",
"version": ">= 9.0.0, < 9.7.0-alpha.11"
}
]
}
]
}
],
"published": "2026-03-31T15:16:20.010",
"references": [
{
"url": "https://github.com/parse-community/parse-server/commit/4fc48cf28f22eea200d74d883505f485234a48d7",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/parse-community/parse-server/commit/dc59e272665644083c5b7f6862d88ce1ef0b2674",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/parse-community/parse-server/pull/10342",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/parse-community/parse-server/pull/10343",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6",
"tags": [
"Mitigation",
"Patch",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending \"prototype.constructor\" to the function name in the URL. When a Cloud Function handler is declared using the function keyword and its validator is a plain object or arrow function, the trigger store traversal resolves the handler through its own prototype chain while the validator store fails to mirror this traversal, causing all access control enforcement to be skipped. This allows unauthenticated callers to invoke Cloud Functions that are meant to be protected by validators such as requireUser, requireMaster, or custom validation logic. This issue has been patched in versions 8.6.67 and 9.7.0-alpha.11."
},
{
"lang": "es",
"value": "Parse Server es un backend de código abierto que puede ser desplegado en cualquier infraestructura que pueda ejecutar Node.js. Antes de las versiones 8.6.67 y 9.7.0-alpha.11, un atacante puede eludir los controles de acceso del validador de Cloud Function al añadir 'prototype.constructor' al nombre de la función en la URL. Cuando un gestor de Cloud Function es declarado usando la palabra clave function y su validador es un objeto plano o una función flecha, el recorrido del almacén de disparadores resuelve el gestor a través de su propia cadena de prototipos mientras que el almacén del validador no logra reflejar este recorrido, lo que provoca que se omita toda la aplicación del control de acceso. Esto permite a los llamadores no autenticados invocar Cloud Functions que están destinadas a ser protegidas por validadores como requireUser, requireMaster, o lógica de validación personalizada. Este problema ha sido parcheado en las versiones 8.6.67 y 9.7.0-alpha.11."
}
],
"lastModified": "2026-07-24T20:10:00.147",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "6BDF8B9B-281F-44DC-9EE0-ED551490D6D8",
"versionEndExcluding": "8.6.67"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "E3DFF698-B3EE-4DCA-BAF3-9BE52F0F77D7",
"versionEndExcluding": "9.7.0",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "3A140D3A-AECC-4CA1-958C-3CA53E313B27"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha10:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "80D441B8-3B25-40E5-82E2-71E2A5E2F58F"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "BEDAEFBC-DA77-4998-BDD6-A139E15E5CC3"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8C9E59AF-3B82-4D61-847B-A18E7DDF7A34"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "2AB743CC-D168-4313-A5AA-43CF76D178E0"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha5:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "C351C736-AB91-4985-A0B4-43B120F5E5C5"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha6:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "F02797C9-E67D-4BF4-BB56-8D6DA9178322"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha7:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B059E381-D0F6-4425-92C0-167486379A98"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha8:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "98C19734-3607-467D-9677-10A1909A8D8D"
},
{
"criteria": "cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha9:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "F55001C0-EDDA-45D9-ABA4-CFF0489C9C01"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}