CVE-2026-32742: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-32742 is a session field overwrite vulnerability in Parse Server, an open-source Node.js backend framework, that allows authenticated users to overwrite server-generated session fields (sessionToken, expiresAt, createdWith) when creating a session object via POST /classes/_Session. This enables bypassing the server's session expiration policy by setting an arbitrary far-future expiration date, and allows setting a predictable session token value. The vulnerability affects Parse Server versions prior to 8.6.42 and versions 9.0.0 through 9.6.0-alpha.16. It was published on March 16, 2026, and has a CVSS v3.1 base score of 4.3 (Moderate) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is classified as CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes): the POST /classes/_Session endpoint in src/RestWrite.js did not filter out server-managed fields (sessionToken, expiresAt, createdWith) from user-supplied request body data before persisting the session object. An authenticated attacker can craft a POST request to the session creation endpoint including arbitrary values for these fields, which the server then accepts and stores without validation. The fix, implemented in PR #10195 (v9) and PR #10196 (v8), expands the set of excluded keys in RestWrite.prototype.handleSession to strip these fields from additionalSessionData before processing (GitHub Advisory, Parse Server PR #10195, Parse Server PR #10196).

Impact

Successful exploitation allows an authenticated attacker to undermine the integrity of the session management system. By setting expiresAt to a far-future date, an attacker can create sessions that never expire, effectively bypassing the server's session expiration policy. By supplying a predictable sessionToken value, an attacker could facilitate session hijacking or token prediction attacks against other users. There is no direct confidentiality or availability impact, but the integrity of authentication controls across all applications built on the affected Parse Server instance is compromised (GitHub Advisory, Parse Server Advisory).

Exploitability

Exploitation requires a valid authenticated session (low privileges), no user interaction, and is achievable over the network with low attack complexity. No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.021% (6th percentile), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Authenticate: Obtain a valid session token for any user account on the target Parse Server instance (e.g., via normal login through the Parse API).
  2. Craft malicious session creation request: Send a POST request to http://<parse-server-host>/1/classes/_Session with the X-Parse-Session-Token header set to the attacker's valid session token and a JSON body containing overridden fields, for example:
    {
      "expiresAt": { "__type": "Date", "iso": "2099-12-31T23:59:59.000Z" },
      "sessionToken": "r:predictable_token_value",
      "createdWith": { "action": "login", "authProvider": "password" }
    }
  3. Verify overwrite: Retrieve the newly created session (using the master key or the session's objectId from the POST response) and confirm that the server stored the attacker-supplied values for expiresAt and sessionToken.
  4. Abuse persistent session: Use the predictable or non-expiring session token to maintain persistent, long-lived access to the application, bypassing any session expiration enforcement (GitHub Advisory, Parse Server PR #10195).

Indicators of compromise

  • Network: Unusual POST requests to /1/classes/_Session (or /classes/_Session) containing JSON bodies with expiresAt, sessionToken, or createdWith fields from authenticated but non-administrative users.
  • Logs: Parse Server access logs showing POST /classes/_Session requests with response 201 Created, followed by session records with far-future expiresAt dates or non-standard sessionToken formats.
  • Database: Session records in the _Session collection/table with expiresAt values set far in the future (e.g., year 2099+), or sessionToken values that do not match the server's standard token generation format (typically r:<random_string>).
  • Application Behavior: Authenticated sessions that remain valid well beyond the configured session expiration window, or multiple sessions sharing suspiciously similar or predictable token values.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.42 (LTS) or 9.6.0-alpha.17 (or later stable 9.6.0) to apply the official fix, which filters server-generated fields from user-supplied session creation data (Parse Server PR #10195, Parse Server PR #10196). As a temporary workaround for deployments that cannot immediately upgrade, add a beforeSave trigger on the _Session class to validate and reject or strip any user-supplied values for sessionToken, expiresAt, and createdWith (GitHub Advisory). Prioritize upgrading to the stable 9.6.0 release, which also addresses numerous other security issues in Parse Server.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management