CVE-2026-33042: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-33042 is an improper authentication vulnerability in Parse Server (an open-source Node.js backend) that allows unauthenticated users to create accounts and obtain authenticated sessions without providing valid credentials. By sending an empty authData object during signup, an attacker can bypass the username and password requirement — even when anonymous user creation is explicitly disabled. The vulnerability affects all Parse Server versions before 8.6.49 and versions 9.0.0 through 9.6.0-alpha.28 (for Node.js). It was disclosed on March 16, 2026, and carries a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is improper authentication (CWE-287) in Parse Server's RestWrite.js signup logic. When a user registration request includes an authData field set to an empty object ({}), the server incorrectly treats this as a valid (but empty) authentication provider context, bypassing the credential validation path that would otherwise require a username and password. The fix introduces a hasAuthData flag that checks whether any provider object with actual keys is present; empty or non-actionable authData is now treated equivalently to absent authData, enforcing username/password requirements when no valid auth provider data exists. The vulnerability is exploitable remotely with no privileges or user interaction required (GitHub Advisory, Parse Server PR #10219).

Impact

Successful exploitation allows an attacker to create user accounts and obtain valid authenticated session tokens on a Parse Server instance without supplying any credentials, circumventing even configurations that disable anonymous user creation. The primary impact is an integrity violation — unauthorized accounts are created in the system — though there is no direct confidentiality or availability impact from the signup bypass itself. Depending on the application's access control model, attacker-controlled sessions could be leveraged to access user-restricted data or functionality, potentially enabling further abuse (GitHub Advisory, Parse Server Advisory).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for CVE-2026-33042. The EPSS score is approximately 0.039% (2nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no special privileges, and no user interaction, making it trivially exploitable by any network-accessible attacker against unpatched instances (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances (e.g., via Shodan searching for Parse Server API endpoints) running versions prior to 8.6.49 or between 9.0.0 and 9.6.0-alpha.28.
  2. Craft malicious signup request: Send an HTTP POST request to the Parse Server user signup endpoint (/1/users) with the Content-Type: application/json header and the application's X-Parse-Application-Id and X-Parse-REST-API-Key headers.
  3. Submit empty authData payload: Include a JSON body with an empty authData object and no username or password fields, e.g.:
{"authData": {}}
  1. Receive session token: The server, failing to validate that no actionable auth provider is present, creates a new user record and returns a valid sessionToken in the HTTP 201 response.
  2. Use session: Use the returned sessionToken in subsequent API requests (via the X-Parse-Session-Token header) to interact with the Parse Server as an authenticated user (GitHub Advisory, Parse Server PR #10219).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /1/users with a JSON body containing {"authData": {}} or similar empty/minimal authData structures; HTTP 201 responses to such requests from the Parse Server.
  • Logs: Parse Server access logs showing user creation events (POST /1/users) with no associated username, password, or recognized auth provider; session tokens issued without corresponding credential fields in the request body.
  • Application Data: Presence of user records in the _User collection/table with no username, password (hashed), or valid authData provider entries, but with associated active sessions in the _Session collection.

Mitigation and workarounds

Parse Server has released patched versions 8.6.49 (LTS branch) and 9.6.0-alpha.29 (and the subsequent stable 9.6.0) that resolve this vulnerability. Upgrading to one of these versions is the recommended remediation. As an interim workaround for deployments that cannot immediately upgrade, administrators should add a Cloud Code beforeSave trigger on the _User class to reject signup requests where authData is empty and no username/password is provided (GitHub Advisory, Parse Server Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management