
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34224 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Parse Server, an open-source Node.js backend platform, that allows an attacker to bypass the single-use guarantee of MFA recovery codes and SMS one-time passwords. By sending concurrent login requests to the authData login endpoint, an attacker possessing a valid authentication provider token and a single MFA recovery code or SMS OTP can create multiple authenticated sessions simultaneously. The vulnerability affects all Parse Server versions before 8.6.64 (8.x branch) and versions 9.0.0 through 9.7.0-alpha.7 (9.x branch). It was disclosed on March 26, 2026, and carries a CVSS v3.1 base score of 4.4 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory).
The root cause is a TOCTOU race condition (CWE-367) in RestWrite.prototype.handleAuthData within src/RestWrite.js. When multiple concurrent POST requests are made to the /users endpoint using the same MFA recovery code, the server reads the current state of the MFA token array before any request has consumed it, then all concurrent requests proceed to update the database — each believing the token is still valid. Because no atomic check-and-consume mechanism existed, all concurrent requests could succeed before any single one had marked the recovery code as used. The fix introduces optimistic locking by capturing a snapshot of the original authData array fields before mutation and including those original values as additional WHERE clause predicates in the database update query; if the record has already been modified by a concurrent request, the update finds no matching document and returns OBJECT_NOT_FOUND, which is translated to a SCRIPT_FAILED / "Invalid auth data" error (GitHub Advisory, Patch PR #10326).
Successful exploitation allows an authenticated attacker — one who has already obtained a valid third-party authentication provider token and a single MFA recovery code or SMS OTP — to create multiple persistent authenticated sessions simultaneously, effectively bypassing MFA protections. Even if the legitimate account owner detects and revokes the unauthorized sessions, the attacker's remaining sessions persist, enabling continued unauthorized access to the user account. The integrity impact is high within the affected system scope, as the attacker can perform any privileged actions available to the compromised account; there is no direct confidentiality or availability impact from the vulnerability itself (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of this report (GitHub Advisory). Exploitation requires the attacker to already possess both a valid authentication provider token for the target account and at least one MFA recovery code or SMS OTP, making opportunistic exploitation unlikely. The EPSS score is approximately 0.062% (0.018% per GitHub Advisory), placing it in a low percentile for near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.
POST /1/users.authData field containing both the third-party provider credentials and the MFA recovery code, e.g.:{
"authData": {
"fakeProvider": { "id": "user1", "token": "<stolen_token>" },
"mfa": { "token": "<recovery_code>" }
}
}curl with parallel execution, a script using Promise.allSettled in Node.js, or a load-testing tool (e.g., ab, wrk) to fire 10 or more identical requests simultaneously before any single request can consume the recovery code./1/users (or the configured Parse Server users endpoint) from the same source IP within milliseconds, all containing identical authData payloads including the same MFA recovery code or SMS OTP.200 OK responses to concurrent POST /1/users requests using the same authentication provider token and MFA token within a very short time window; subsequent session activity from geographically or device-profile-disparate locations.Upgrade Parse Server immediately to version 8.6.64 (for the 8.x LTS branch) or 9.7.0-alpha.8 or later (for the 9.x branch, with stable 9.7.0 also containing the fix) (GitHub Advisory, Patch PR #10327). The GitHub Advisory notes there is no known configuration-based workaround; however, as an interim measure, implementing rate limiting on the authData login endpoint to prevent concurrent authentication requests from the same token can reduce exploitation risk. Additionally, monitoring authentication logs for patterns of multiple session creation from the same MFA credential and enabling device fingerprinting or geographic anomaly detection can help identify suspicious activity until patching is complete.
The vulnerability was reported and patched by Parse Server maintainer mtrezza on March 26, 2026, with fixes simultaneously released for both the 8.x LTS and 9.x alpha branches (Patch PR #10326, Patch PR #10327). The fix was included in the stable Parse Server 9.7.0 release on March 30, 2026, alongside several other security fixes. No significant broader community or media commentary has been identified beyond the GitHub advisory and standard CVE tracking databases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."