
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33042 is an improper authentication vulnerability in Parse Server (an open-source Node.js backend) that allows unauthenticated users to create accounts and obtain authenticated sessions without providing valid credentials. By sending an empty authData object during signup, an attacker can bypass the username and password requirement — even when anonymous user creation is explicitly disabled. The vulnerability affects all Parse Server versions before 8.6.49 and versions 9.0.0 through 9.6.0-alpha.28 (for Node.js). It was disclosed on March 16, 2026, and carries a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, Parse Server Advisory).
The root cause is improper authentication (CWE-287) in Parse Server's RestWrite.js signup logic. When a user registration request includes an authData field set to an empty object ({}), the server incorrectly treats this as a valid (but empty) authentication provider context, bypassing the credential validation path that would otherwise require a username and password. The fix introduces a hasAuthData flag that checks whether any provider object with actual keys is present; empty or non-actionable authData is now treated equivalently to absent authData, enforcing username/password requirements when no valid auth provider data exists. The vulnerability is exploitable remotely with no privileges or user interaction required (GitHub Advisory, Parse Server PR #10219).
Successful exploitation allows an attacker to create user accounts and obtain valid authenticated session tokens on a Parse Server instance without supplying any credentials, circumventing even configurations that disable anonymous user creation. The primary impact is an integrity violation — unauthorized accounts are created in the system — though there is no direct confidentiality or availability impact from the signup bypass itself. Depending on the application's access control model, attacker-controlled sessions could be leveraged to access user-restricted data or functionality, potentially enabling further abuse (GitHub Advisory, Parse Server Advisory).
No public exploit code or in-the-wild exploitation has been reported for CVE-2026-33042. The EPSS score is approximately 0.039% (2nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no special privileges, and no user interaction, making it trivially exploitable by any network-accessible attacker against unpatched instances (GitHub Advisory).
/1/users) with the Content-Type: application/json header and the application's X-Parse-Application-Id and X-Parse-REST-API-Key headers.authData object and no username or password fields, e.g.:{"authData": {}}sessionToken in the HTTP 201 response.sessionToken in subsequent API requests (via the X-Parse-Session-Token header) to interact with the Parse Server as an authenticated user (GitHub Advisory, Parse Server PR #10219)./1/users with a JSON body containing {"authData": {}} or similar empty/minimal authData structures; HTTP 201 responses to such requests from the Parse Server.POST /1/users) with no associated username, password, or recognized auth provider; session tokens issued without corresponding credential fields in the request body._User collection/table with no username, password (hashed), or valid authData provider entries, but with associated active sessions in the _Session collection.Parse Server has released patched versions 8.6.49 (LTS branch) and 9.6.0-alpha.29 (and the subsequent stable 9.6.0) that resolve this vulnerability. Upgrading to one of these versions is the recommended remediation. As an interim workaround for deployments that cannot immediately upgrade, administrators should add a Cloud Code beforeSave trigger on the _User class to reject signup requests where authData is empty and no username/password is provided (GitHub Advisory, Parse Server Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."