
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32742 is a session field overwrite vulnerability in Parse Server, an open-source Node.js backend framework, that allows authenticated users to overwrite server-generated session fields (sessionToken, expiresAt, createdWith) when creating a session object via POST /classes/_Session. This enables bypassing the server's session expiration policy by setting an arbitrary far-future expiration date, and allows setting a predictable session token value. The vulnerability affects Parse Server versions prior to 8.6.42 and versions 9.0.0 through 9.6.0-alpha.16. It was published on March 16, 2026, and has a CVSS v3.1 base score of 4.3 (Moderate) (GitHub Advisory, Parse Server Advisory).
The root cause is classified as CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes): the POST /classes/_Session endpoint in src/RestWrite.js did not filter out server-managed fields (sessionToken, expiresAt, createdWith) from user-supplied request body data before persisting the session object. An authenticated attacker can craft a POST request to the session creation endpoint including arbitrary values for these fields, which the server then accepts and stores without validation. The fix, implemented in PR #10195 (v9) and PR #10196 (v8), expands the set of excluded keys in RestWrite.prototype.handleSession to strip these fields from additionalSessionData before processing (GitHub Advisory, Parse Server PR #10195, Parse Server PR #10196).
Successful exploitation allows an authenticated attacker to undermine the integrity of the session management system. By setting expiresAt to a far-future date, an attacker can create sessions that never expire, effectively bypassing the server's session expiration policy. By supplying a predictable sessionToken value, an attacker could facilitate session hijacking or token prediction attacks against other users. There is no direct confidentiality or availability impact, but the integrity of authentication controls across all applications built on the affected Parse Server instance is compromised (GitHub Advisory, Parse Server Advisory).
Exploitation requires a valid authenticated session (low privileges), no user interaction, and is achievable over the network with low attack complexity. No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.021% (6th percentile), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
POST request to http://<parse-server-host>/1/classes/_Session with the X-Parse-Session-Token header set to the attacker's valid session token and a JSON body containing overridden fields, for example:{
"expiresAt": { "__type": "Date", "iso": "2099-12-31T23:59:59.000Z" },
"sessionToken": "r:predictable_token_value",
"createdWith": { "action": "login", "authProvider": "password" }
}expiresAt and sessionToken.POST requests to /1/classes/_Session (or /classes/_Session) containing JSON bodies with expiresAt, sessionToken, or createdWith fields from authenticated but non-administrative users.POST /classes/_Session requests with response 201 Created, followed by session records with far-future expiresAt dates or non-standard sessionToken formats._Session collection/table with expiresAt values set far in the future (e.g., year 2099+), or sessionToken values that do not match the server's standard token generation format (typically r:<random_string>).Upgrade Parse Server to version 8.6.42 (LTS) or 9.6.0-alpha.17 (or later stable 9.6.0) to apply the official fix, which filters server-generated fields from user-supplied session creation data (Parse Server PR #10195, Parse Server PR #10196). As a temporary workaround for deployments that cannot immediately upgrade, add a beforeSave trigger on the _Session class to validate and reject or strip any user-supplied values for sessionToken, expiresAt, and createdWith (GitHub Advisory). Prioritize upgrading to the stable 9.6.0 release, which also addresses numerous other security issues in Parse Server.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."