
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30229 is an incorrect authorization vulnerability in Parse Server, an open-source backend framework for Node.js, where the readOnlyMasterKey credential is improperly permitted to call the POST /loginAs endpoint to obtain valid session tokens for arbitrary users. This effectively allows a read-only credential to escalate privileges and impersonate any user with full read and write access to their data. Affected versions include all Parse Server releases prior to 8.6.6 and versions 9.0.0 through 9.5.0-alpha.3 (inclusive of alpha1, alpha2, alpha3). The vulnerability was published on March 5, 2026, and has a CVSS v4.0 base score of 8.5 (High) and a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization): the /loginAs endpoint handler in Parse Server fails to verify whether the requesting credential is the readOnlyMasterKey before issuing a session token, allowing it to bypass the intended read-only restriction. The attack vector is network-based and requires the attacker to possess the readOnlyMasterKey (a high-privilege precondition), but no user interaction is needed. The fix, applied in versions 8.6.6 and 9.5.0-alpha.4, adds an explicit authorization check in the /logInAs handler to block readOnlyMasterKey from invoking this endpoint (GitHub Advisory, Github Advisory).
Successful exploitation allows an attacker holding the readOnlyMasterKey to impersonate any user on the Parse Server instance, gaining full read and write access to that user's data — a critical privilege escalation from a nominally read-only credential. This can result in unauthorized data exfiltration, data manipulation or deletion, and account takeover for any user in the system. Any Parse Server deployment that configures and exposes the readOnlyMasterKey is at risk, and the scope of impact extends to all user data managed by the affected server (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of reporting (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.024% (7th percentile), indicating a low near-term probability of exploitation (Github Advisory). Exploitation requires possession of the readOnlyMasterKey, which limits the attacker pool to those with access to this credential.
readOnlyMasterKey for the target Parse Server instance through credential theft, misconfiguration exposure, or insider access.readOnlyMasterKey for read access to the _User class) to identify the objectId of the user to impersonate.POST /loginAs request to the Parse Server API, authenticating with the readOnlyMasterKey and specifying the target user's objectId:POST /1/loginAs
X-Parse-Master-Key: <readOnlyMasterKey>
Content-Type: application/json
{"userId": "<target_user_objectId>"}X-Parse-Session-Token: <token>) to read, modify, or delete the target user's data with full privileges (GitHub Advisory).POST /1/loginAs (or /loginAs) requests in Parse Server access logs, particularly those authenticated with the readOnlyMasterKey rather than the standard masterKey.POST /loginAs calls followed by session token issuance for users not initiated by an administrator; repeated or automated calls to /loginAs from the same source IP./loginAs using the readOnlyMasterKey.Upgrade Parse Server to version 8.6.6 (for the 8.x branch) or 9.5.0-alpha.4 (for the 9.x branch), which add an authorization check in the /logInAs handler to block readOnlyMasterKey from calling this endpoint (Parse Server 8.6.6 Release, Parse Server 9.5.0-alpha.4 Release). The official advisory states there is no workaround other than not using readOnlyMasterKey at all (GitHub Advisory). For deployments unable to patch immediately, restrict network access to the Parse Server instance, review access logs for unauthorized /loginAs calls using readOnlyMasterKey, and rotate all readOnlyMasterKey credentials.
The vulnerability was reported by researcher devanshbatham and coordinated by mtrezza from the Parse community (GitHub Advisory). The researcher published a blog post about the finding at devansh.bearblog.dev. Coverage appeared on security aggregators and community platforms including Bluesky and vulnerability digest sites shortly after disclosure, though no major media coverage or significant social media controversy has been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."