
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30863 is a JWT audience validation bypass vulnerability in Parse Server's Google, Apple, and Facebook authentication adapters. When the adapter's audience configuration option is not set (clientId for Google/Apple, appIds for Facebook), JWT verification silently skips audience claim validation, allowing an attacker to use a validly signed JWT issued for a different application to authenticate as any user on the target Parse Server. Affected versions include all Parse Server releases prior to 8.6.10 and versions 9.0.0 through 9.5.0-alpha.10 for the v9 branch. The vulnerability was published on March 7, 2026, and patched the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, Github Advisory).
The root cause is improper authentication (CWE-287) and incorrect authorization (CWE-863) stemming from the authentication adapters' failure to enforce audience claim validation in JWT verification when the relevant configuration options are absent. For Google and Apple adapters, if clientId is not configured, the JWT library silently skips the audience (aud) claim check, accepting tokens issued for any application signed by the same identity provider. For Facebook Limited Login, the flaw is more severe: the adapter never passed appIds as the audience parameter to JWT verification, making it exploitable regardless of configuration. An attacker only needs a valid JWT from any application using the same OAuth provider (Google, Apple, or Facebook) — no special privileges, user interaction, or complex setup is required. A public proof-of-concept exploit has been published at https://github.com/Worthes/CVE-2026-30863-Exploit (GitHub Advisory, Github Advisory).
Successful exploitation allows an unauthenticated attacker to impersonate any user on the affected Parse Server instance, including administrators, by presenting a validly signed JWT from a different application. This results in full compromise of confidentiality and integrity of user data — attackers can read, modify, or delete any user's data stored on the server. While availability is not directly impacted, account hijacking at scale could enable lateral movement within the application, unauthorized access to sensitive user records, and complete takeover of the backend service (GitHub Advisory, Github Advisory).
A public proof-of-concept exploit is available at https://github.com/Worthes/CVE-2026-30863-Exploit, published shortly after the vulnerability was disclosed. The EPSS score is approximately 0.034–0.066%, indicating a currently low but non-negligible probability of exploitation in the wild within 30 days. No confirmed in-the-wild exploitation or threat actor attribution has been reported as of the time of this report, and the vulnerability is not listed in the CISA KEV catalog. The attack requires no privileges or user interaction and is exploitable remotely over the network, making it highly accessible to opportunistic attackers (Github Advisory, GitHub Advisory).
POST /1/users) using the social login adapter, supplying the attacker-controlled JWT and the target user's identity claim.aud claim (due to missing clientId/appIds configuration), the token is accepted as valid, and the server authenticates the attacker as the target user.POST /1/users requests using social login (authData) payloads from unexpected IP addresses or geographic locations; authentication requests where the JWT aud claim does not match the server's configured clientId or appIds.Upgrade Parse Server to version 8.6.10 or 9.5.0-alpha.11 (or later), which enforce clientId (Google/Apple) and appIds (Facebook) as mandatory parameters and pass them to JWT verification for audience validation. As a partial workaround for Google and Apple adapters on unpatched versions, ensure clientId is explicitly set in the adapter configuration — this causes JWT verification to correctly validate the audience claim. There is no workaround for Facebook Limited Login; upgrading is the only mitigation for that adapter. Administrators should also audit their Parse Server configuration to confirm all social authentication adapters have the required audience parameters set (GitHub Advisory, Github Advisory).
The vulnerability received coverage from security blogs and vulnerability digest sites shortly after disclosure, including a write-up at infinitsec.net and a video overview at undercodetesting.com covering the CVE-2026 Parse Server series. The security community noted the severity of the Facebook Limited Login variant, which has no configuration-based workaround. Social media activity was observed on Bluesky and Mastodon/Infosec.exchange, with researchers highlighting the ease of exploitation given the zero-privilege requirement. The advisory credits researcher devanshbatham as the finder and asukachloe as the reporter (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."