
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31875 is a logic flaw in Parse Server's MFA recovery code handling, where TOTP-based recovery codes are not invalidated after use, allowing unlimited reuse. It affects Parse Server (npm) versions < 8.6.33 and >= 9.0.0 < 9.6.0-alpha.7 for Node.js. The vulnerability was disclosed on March 10, 2026, by researcher 0xkakash1 and coordinated by mtrezza. It carries a CVSS v4 base score of 8.2 (High) and a CVSS v3.1 base score of 5.9 (Medium) (GitHub Advisory, Parse Server Advisory).
The root cause is classified as CWE-672 (Operation on a Resource after Expiration or Release): Parse Server generates two single-use recovery codes when TOTP-based MFA is enabled, but fails to remove a recovery code from the stored list after it is successfully used for authentication. As a result, the same code remains valid indefinitely and can be submitted repeatedly via the network authentication endpoint without any additional privileges or user interaction. The fix, applied in versions 8.6.33 and 9.6.0-alpha.7, ensures each recovery code is deleted from the stored list immediately after a successful login (GitHub Advisory, Parse Server Advisory).
Successful exploitation allows an attacker who has obtained a single MFA recovery code to authenticate repeatedly as the affected user without the code ever being invalidated, effectively bypassing the MFA protection entirely. The primary impact is a high confidentiality risk — the attacker gains persistent, unauthorized access to the user's account and all data accessible through it. Integrity and availability of the system are not directly impacted by this vulnerability, but persistent unauthorized access could enable further actions such as data exfiltration or account takeover (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.139% (34th percentile), indicating a low near-term exploitation probability. Exploitation requires the attacker to first obtain a valid recovery code through phishing, credential theft, or other means, which raises the practical attack complexity (GitHub Advisory).
/1/login or equivalent) on the target deployment.Parse Server has released patched versions 8.6.33 (for the 8.x branch) and 9.6.0-alpha.7 (for the 9.x alpha branch), both published on March 10, 2026. There is no known configuration-based workaround — upgrading to a patched version is the only remediation. After patching, administrators should audit authentication logs for suspicious recovery code reuse, revoke and regenerate all existing MFA recovery codes for affected users, and monitor for anomalous login patterns (Parse Server 8.6.33, Parse Server 9.6.0-alpha.7).
The vulnerability was reported by security researcher 0xkakash1 and coordinated by Parse Server maintainer mtrezza, with the advisory published directly through GitHub's security advisory process. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."