
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33627 is an information disclosure vulnerability in Parse Server (open source Node.js backend) where the GET /users/me endpoint returns unsanitized authentication data — including MFA TOTP secrets and recovery codes — to authenticated users. It affects all Parse Server versions prior to 8.6.61 and versions 9.0.0 through 9.6.0-alpha.54. The vulnerability was published on March 22, 2026 (GitHub Advisory) and March 24, 2026 (NVD). It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory).
The root cause (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) lies in the handleMe() method of UsersRouter.js. The original implementation queried the _Session collection using master-level authentication with { include: 'user' }, causing the master context to propagate into the user data fetch and bypass auth adapter sanitization (specifically the afterFind hook). As a result, sensitive fields such as MFA TOTP secrets (authData.mfa.secret) and recovery codes (authData.mfa.recovery) were returned in the API response without being filtered. Exploitation requires only a valid session token — obtainable via normal login — and a simple GET /users/me HTTP request with the X-Parse-Session-Token header (GitHub Advisory, Fix PR #10279).
An authenticated attacker who obtains any user's session token can call GET /users/me to extract that user's raw MFA TOTP secret and recovery codes. With the TOTP secret, the attacker can generate valid one-time codes indefinitely, effectively bypassing multi-factor authentication and enabling persistent account takeover. This is a confidentiality-only impact with no direct integrity or availability consequences, but the downstream effect of MFA bypass can expose all data and functionality accessible to the compromised account (GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires low privileges (a valid session token) and no user interaction, making it straightforward to exploit once a session token is obtained. The EPSS score is approximately 0.093%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
POST /login) to receive a session token in the response.GET /users/me request to the Parse Server with the session token in the X-Parse-Session-Token header:GET /1/users/me HTTP/1.1
Host: <parse-server-host>
X-Parse-Application-Id: <app-id>
X-Parse-Session-Token: <session-token>authData, e.g.:{ "authData": { "mfa": { "secret": "<BASE32_TOTP_SECRET>", "recovery": ["<code1>", "<code2>"] } } }secret with any TOTP library (e.g., otpauth in Node.js or Google Authenticator) to generate valid one-time codes indefinitely.GET /1/users/me requests from IP addresses not associated with the legitimate user's normal activity; requests using session tokens belonging to other users.GET /users/me requests returning authData fields containing secret or recovery keys (visible in debug/verbose logging); requests from unexpected geographic locations or user agents.GET /users/me request from an anomalous source.Upgrade Parse Server immediately to version 8.6.61 (for 8.x installations) or 9.6.0-alpha.55 or later (for 9.x installations). The fix refactors handleMe() to perform a two-step fetch: the _Session is queried with master key (without including user data), and the user is then re-fetched separately using the caller's own authentication context, ensuring all security layers (protectedFields, CLP, auth adapter afterFind) apply correctly. There is no known workaround — patching is the only remediation. Additionally, administrators should rotate MFA secrets and recovery codes for any users who may have been affected, and implement monitoring for anomalous GET /users/me requests (GitHub Advisory, Fix PR #10278, Fix PR #10279).
The vulnerability was discovered and reported by Parse Server maintainer mtrezza, who also authored the fix. The advisory was published quietly alongside a large batch of security fixes included in the Parse Server 9.6.0 stable release, which addressed over 50 security issues simultaneously. No significant independent researcher commentary or broad media coverage has been identified beyond standard CVE tracking and aggregator sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."