
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30850 is a missing authorization vulnerability in Parse Server, an open-source Node.js backend platform, where the file metadata endpoint (GET /files/:appId/metadata/:filename) fails to enforce beforeFind / afterFind file triggers used as access-control gates. This allows unauthenticated remote attackers to access protected file metadata without authorization. Affected versions include all Parse Server releases before 8.6.9 and versions 9.0.0 through 9.5.0-alpha.8. It was published on March 7, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 score of 5.9 (Medium) and a CVSS v4.0 score of 6.3 (Medium) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-862 (Missing Authorization): the metadata route handler in Parse Server does not invoke beforeFind or afterFind cloud triggers before returning file metadata, meaning any access-control logic implemented in those triggers is silently bypassed (GitHub Advisory). An attacker can exploit this by sending an unauthenticated HTTP GET request directly to /files/:appId/metadata/:filename, circumventing application-level restrictions that would normally be enforced via Parse.Cloud.beforeFind(Parse.File, ...). The vulnerability only exposes user-defined key-value metadata set via addMetadata; actual file content is not accessible through this endpoint. The fix involves the metadata handler now running beforeFind and afterFind triggers and returning HTTP 403 when a trigger denies access (Github Advisory).
Successful exploitation allows an unauthenticated network attacker to read file metadata (user-defined key-value pairs) that should be protected by application-level access controls, resulting in a confidentiality impact. File content itself remains protected, limiting the scope of data exposure to metadata only. Depending on what sensitive information is stored in file metadata (e.g., internal identifiers, classification labels, user-associated data), this could facilitate reconnaissance or further targeted attacks against the application or its users (GitHub Advisory, Github Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The vulnerability requires no authentication and no user interaction, making it straightforward to exploit against any internet-accessible Parse Server instance that uses beforeFind/afterFind triggers for file access control. The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been reported.
:appId) from the target Parse Server deployment, which may be discoverable through application source code, API responses, or prior reconnaissance.GET /parse/files/<appId>/metadata/<filename> HTTP/1.1
Host: <target-parse-server>addMetadata) without invoking beforeFind/afterFind triggers, bypassing any access-control logic implemented in those triggers./files/*/metadata/* endpoints from external or unexpected IP addresses; absence of authentication headers in requests to the metadata route.GET /files/:appId/metadata/:filename requests returning HTTP 200 responses from IPs not associated with legitimate users or services; high volume of metadata endpoint requests across multiple filenames (enumeration behavior).beforeFind/afterFind triggers are configured to deny access.Upgrade Parse Server to version 8.6.9 (for the 8.x branch) or 9.5.0-alpha.9 (for the 9.x branch), which enforce beforeFind/afterFind triggers on the metadata endpoint and return HTTP 403 on denied access (GitHub Advisory). For deployments that cannot patch immediately, add a middleware route before mounting Parse Server to block all metadata endpoint requests:
// Add before mounting Parse Server
app.get('/parse/files/:appId/metadata/:filename', (req, res) => {
res.status(403).json({ error: 'Forbidden' });
});Adjust the /parse path prefix to match your configured mountPath. Additionally, implement network-level access controls or WAF rules to restrict access to /files/*/metadata/* endpoints from untrusted sources.
The vulnerability was reported by researcher fancymalware and coordinated by mtrezza (a Parse Server maintainer), with the advisory published directly to the parse-community GitHub repository on March 7, 2026 (GitHub Advisory). No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."