
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31901 is a user enumeration vulnerability in Parse Server (npm package by parse-community) affecting the email verification endpoint (/verificationEmailRequest). The endpoint returns distinct error responses depending on whether an email address belongs to an existing user, is already verified, or does not exist — allowing unauthenticated attackers to enumerate registered email addresses. It affects all Parse Server versions below 8.6.34 and versions 9.0.0 through below 9.6.0-alpha.8, and only impacts deployments with email verification enabled (verifyUserEmails: true). The vulnerability was published on March 10, 2026, with a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 6.3 (Medium) (Github Advisory, Parse Server Advisory).
The root cause is classified as CWE-204 (Observable Response Discrepancy): the /verificationEmailRequest endpoint leaks internal application state by returning different HTTP error codes or response bodies depending on whether the submitted email address is unregistered, registered but unverified, or already verified. An unauthenticated remote attacker can exploit this by sending automated HTTP requests with different email addresses and observing the response codes to determine which addresses are registered in the system. No authentication, special privileges, or user interaction is required; the only precondition is that the target Parse Server instance has verifyUserEmails: true configured. The vulnerability was reported by researcher 0xkakash1 and analyzed by mtrezza (Parse Server Advisory, Github Advisory).
Successful exploitation allows an unauthenticated attacker to enumerate valid email addresses registered in the application, resulting in a low confidentiality impact with no integrity or availability impact. The disclosed information (confirmed registered email addresses) can be leveraged for downstream attacks such as targeted phishing, credential stuffing, or brute-force login attempts against identified accounts. The vulnerability's scope is limited to Parse Server deployments with email verification enabled, and there is no evidence of lateral movement or direct data exfiltration beyond user account enumeration (Parse Server Advisory).
No public proof-of-concept exploit code or exploit kits have been identified for this vulnerability. There is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.044% (14th percentile), indicating a low near-term exploitation probability (Github Advisory). No threat actor attribution has been reported.
verifyUserEmails: true enabled./verificationEmailRequest endpoint of the Parse Server instance:POST /verificationEmailRequest HTTP/1.1
Host: <target-parse-server>
Content-Type: application/json
{"email": "candidate@example.com"}/verificationEmailRequest from a single IP or a distributed set of IPs, especially with many different email addresses in a short time window./verificationEmailRequest with varying email parameters and differing response codes (e.g., 400, 404, 200) across requests from the same source.Parse Server has released patched versions 8.6.34 (for the 8.x branch) and 9.6.0-alpha.8 (for the 9.x alpha branch), both published on March 10, 2026. The fix introduces a new server option emailVerifySuccessOnInvalidEmail (default: true) that returns a generic success response for all verification email requests regardless of the email's registration status, preventing response-based enumeration. The patch also strengthens input validation for the related resetPasswordSuccessOnInvalidEmail option and adds security warnings when either enumeration mitigation is disabled. There is no known workaround — upgrading to a patched version is the only remediation (Parse Server Advisory, Release 8.6.34, Release 9.6.0-alpha.8).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."