CVE-2026-30863: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-30863 is a JWT audience validation bypass vulnerability in Parse Server's Google, Apple, and Facebook authentication adapters. When the adapter's audience configuration option is not set (clientId for Google/Apple, appIds for Facebook), JWT verification silently skips audience claim validation, allowing an attacker to use a validly signed JWT issued for a different application to authenticate as any user on the target Parse Server. Affected versions include all Parse Server releases prior to 8.6.10 and versions 9.0.0 through 9.5.0-alpha.10 for the v9 branch. The vulnerability was published on March 7, 2026, and patched the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, Github Advisory).

Technical details

The root cause is improper authentication (CWE-287) and incorrect authorization (CWE-863) stemming from the authentication adapters' failure to enforce audience claim validation in JWT verification when the relevant configuration options are absent. For Google and Apple adapters, if clientId is not configured, the JWT library silently skips the audience (aud) claim check, accepting tokens issued for any application signed by the same identity provider. For Facebook Limited Login, the flaw is more severe: the adapter never passed appIds as the audience parameter to JWT verification, making it exploitable regardless of configuration. An attacker only needs a valid JWT from any application using the same OAuth provider (Google, Apple, or Facebook) — no special privileges, user interaction, or complex setup is required. A public proof-of-concept exploit has been published at https://github.com/Worthes/CVE-2026-30863-Exploit (GitHub Advisory, Github Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to impersonate any user on the affected Parse Server instance, including administrators, by presenting a validly signed JWT from a different application. This results in full compromise of confidentiality and integrity of user data — attackers can read, modify, or delete any user's data stored on the server. While availability is not directly impacted, account hijacking at scale could enable lateral movement within the application, unauthorized access to sensitive user records, and complete takeover of the backend service (GitHub Advisory, Github Advisory).

Exploitability

A public proof-of-concept exploit is available at https://github.com/Worthes/CVE-2026-30863-Exploit, published shortly after the vulnerability was disclosed. The EPSS score is approximately 0.034–0.066%, indicating a currently low but non-negligible probability of exploitation in the wild within 30 days. No confirmed in-the-wild exploitation or threat actor attribution has been reported as of the time of this report, and the vulnerability is not listed in the CISA KEV catalog. The attack requires no privileges or user interaction and is exploitable remotely over the network, making it highly accessible to opportunistic attackers (Github Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances (e.g., via Shodan, Censys, or application fingerprinting) running versions prior to 8.6.10 or between 9.0.0 and 9.5.0-alpha.10 that use Google, Apple, or Facebook authentication adapters.
  2. Obtain a valid JWT: Register or log in to any application that uses the same OAuth provider (Google, Apple, or Facebook) to obtain a legitimately signed JWT token. The token does not need to be issued for the target Parse Server application.
  3. Identify target user: Enumerate or guess a valid user identifier (e.g., email or social login ID) on the target Parse Server that corresponds to an account linked via the vulnerable authentication adapter.
  4. Craft authentication request: Submit an authentication request to the Parse Server's login endpoint (e.g., POST /1/users) using the social login adapter, supplying the attacker-controlled JWT and the target user's identity claim.
  5. Bypass audience validation: Because the server does not validate the JWT's aud claim (due to missing clientId/appIds configuration), the token is accepted as valid, and the server authenticates the attacker as the target user.
  6. Achieve account takeover: Receive a Parse session token for the impersonated user and use it to access, modify, or exfiltrate that user's data, or escalate to administrative functions if the target account has elevated privileges (GitHub Advisory, Github Advisory).

Indicators of compromise

  • Network: Unusual or high-volume POST /1/users requests using social login (authData) payloads from unexpected IP addresses or geographic locations; authentication requests where the JWT aud claim does not match the server's configured clientId or appIds.
  • Logs: Parse Server access logs showing successful social login authentications for users from unfamiliar IP addresses or at unusual times; multiple successful logins for the same user from different accounts or providers in a short timeframe.
  • Application Behavior: Unexpected session tokens being issued for high-privilege or administrative accounts; user accounts showing login activity inconsistent with the account owner's normal patterns.
  • File System / Database: Unauthorized modifications to user records or data objects in the Parse database shortly following anomalous authentication events.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.10 or 9.5.0-alpha.11 (or later), which enforce clientId (Google/Apple) and appIds (Facebook) as mandatory parameters and pass them to JWT verification for audience validation. As a partial workaround for Google and Apple adapters on unpatched versions, ensure clientId is explicitly set in the adapter configuration — this causes JWT verification to correctly validate the audience claim. There is no workaround for Facebook Limited Login; upgrading is the only mitigation for that adapter. Administrators should also audit their Parse Server configuration to confirm all social authentication adapters have the required audience parameters set (GitHub Advisory, Github Advisory).

Community reactions

The vulnerability received coverage from security blogs and vulnerability digest sites shortly after disclosure, including a write-up at infinitsec.net and a video overview at undercodetesting.com covering the CVE-2026 Parse Server series. The security community noted the severity of the Facebook Limited Login variant, which has no configuration-based workaround. Social media activity was observed on Bluesky and Mastodon/Infosec.exchange, with researchers highlighting the ease of exploitation given the zero-privilege requirement. The advisory credits researcher devanshbatham as the finder and asukachloe as the reporter (Github Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management