CVE-2026-30229: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-30229 is an incorrect authorization vulnerability in Parse Server, an open-source backend framework for Node.js, where the readOnlyMasterKey credential is improperly permitted to call the POST /loginAs endpoint to obtain valid session tokens for arbitrary users. This effectively allows a read-only credential to escalate privileges and impersonate any user with full read and write access to their data. Affected versions include all Parse Server releases prior to 8.6.6 and versions 9.0.0 through 9.5.0-alpha.3 (inclusive of alpha1, alpha2, alpha3). The vulnerability was published on March 5, 2026, and has a CVSS v4.0 base score of 8.5 (High) and a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): the /loginAs endpoint handler in Parse Server fails to verify whether the requesting credential is the readOnlyMasterKey before issuing a session token, allowing it to bypass the intended read-only restriction. The attack vector is network-based and requires the attacker to possess the readOnlyMasterKey (a high-privilege precondition), but no user interaction is needed. The fix, applied in versions 8.6.6 and 9.5.0-alpha.4, adds an explicit authorization check in the /logInAs handler to block readOnlyMasterKey from invoking this endpoint (GitHub Advisory, Github Advisory).

Impact

Successful exploitation allows an attacker holding the readOnlyMasterKey to impersonate any user on the Parse Server instance, gaining full read and write access to that user's data — a critical privilege escalation from a nominally read-only credential. This can result in unauthorized data exfiltration, data manipulation or deletion, and account takeover for any user in the system. Any Parse Server deployment that configures and exposes the readOnlyMasterKey is at risk, and the scope of impact extends to all user data managed by the affected server (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of reporting (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.024% (7th percentile), indicating a low near-term probability of exploitation (Github Advisory). Exploitation requires possession of the readOnlyMasterKey, which limits the attacker pool to those with access to this credential.

Exploitation steps

  1. Obtain the readOnlyMasterKey: Acquire the readOnlyMasterKey for the target Parse Server instance through credential theft, misconfiguration exposure, or insider access.
  2. Identify target user: Enumerate user accounts on the Parse Server (e.g., via the Parse API using the readOnlyMasterKey for read access to the _User class) to identify the objectId of the user to impersonate.
  3. Call the /loginAs endpoint: Send a POST /loginAs request to the Parse Server API, authenticating with the readOnlyMasterKey and specifying the target user's objectId:
    POST /1/loginAs
    X-Parse-Master-Key: <readOnlyMasterKey>
    Content-Type: application/json
    
    {"userId": "<target_user_objectId>"}
  4. Receive session token: The server responds with a valid session token for the target user, bypassing the intended read-only restriction.
  5. Impersonate the user: Use the obtained session token in subsequent API requests (X-Parse-Session-Token: <token>) to read, modify, or delete the target user's data with full privileges (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected POST /1/loginAs (or /loginAs) requests in Parse Server access logs, particularly those authenticated with the readOnlyMasterKey rather than the standard masterKey.
  • Logs: Parse Server access logs showing POST /loginAs calls followed by session token issuance for users not initiated by an administrator; repeated or automated calls to /loginAs from the same source IP.
  • Logs: Audit entries showing data write or modification operations performed under session tokens that were generated via /loginAs using the readOnlyMasterKey.
  • Network: Unusual API activity (write/delete operations) from session tokens associated with accounts that do not normally perform such actions, potentially indicating impersonation.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.6 (for the 8.x branch) or 9.5.0-alpha.4 (for the 9.x branch), which add an authorization check in the /logInAs handler to block readOnlyMasterKey from calling this endpoint (Parse Server 8.6.6 Release, Parse Server 9.5.0-alpha.4 Release). The official advisory states there is no workaround other than not using readOnlyMasterKey at all (GitHub Advisory). For deployments unable to patch immediately, restrict network access to the Parse Server instance, review access logs for unauthorized /loginAs calls using readOnlyMasterKey, and rotate all readOnlyMasterKey credentials.

Community reactions

The vulnerability was reported by researcher devanshbatham and coordinated by mtrezza from the Parse community (GitHub Advisory). The researcher published a blog post about the finding at devansh.bearblog.dev. Coverage appeared on security aggregators and community platforms including Bluesky and vulnerability digest sites shortly after disclosure, though no major media coverage or significant social media controversy has been noted.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management