CVE-2026-34224: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-34224 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Parse Server, an open-source Node.js backend platform, that allows an attacker to bypass the single-use guarantee of MFA recovery codes and SMS one-time passwords. By sending concurrent login requests to the authData login endpoint, an attacker possessing a valid authentication provider token and a single MFA recovery code or SMS OTP can create multiple authenticated sessions simultaneously. The vulnerability affects all Parse Server versions before 8.6.64 (8.x branch) and versions 9.0.0 through 9.7.0-alpha.7 (9.x branch). It was disclosed on March 26, 2026, and carries a CVSS v3.1 base score of 4.4 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory).

Technical details

The root cause is a TOCTOU race condition (CWE-367) in RestWrite.prototype.handleAuthData within src/RestWrite.js. When multiple concurrent POST requests are made to the /users endpoint using the same MFA recovery code, the server reads the current state of the MFA token array before any request has consumed it, then all concurrent requests proceed to update the database — each believing the token is still valid. Because no atomic check-and-consume mechanism existed, all concurrent requests could succeed before any single one had marked the recovery code as used. The fix introduces optimistic locking by capturing a snapshot of the original authData array fields before mutation and including those original values as additional WHERE clause predicates in the database update query; if the record has already been modified by a concurrent request, the update finds no matching document and returns OBJECT_NOT_FOUND, which is translated to a SCRIPT_FAILED / "Invalid auth data" error (GitHub Advisory, Patch PR #10326).

Impact

Successful exploitation allows an authenticated attacker — one who has already obtained a valid third-party authentication provider token and a single MFA recovery code or SMS OTP — to create multiple persistent authenticated sessions simultaneously, effectively bypassing MFA protections. Even if the legitimate account owner detects and revokes the unauthorized sessions, the attacker's remaining sessions persist, enabling continued unauthorized access to the user account. The integrity impact is high within the affected system scope, as the attacker can perform any privileged actions available to the compromised account; there is no direct confidentiality or availability impact from the vulnerability itself (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of this report (GitHub Advisory). Exploitation requires the attacker to already possess both a valid authentication provider token for the target account and at least one MFA recovery code or SMS OTP, making opportunistic exploitation unlikely. The EPSS score is approximately 0.062% (0.018% per GitHub Advisory), placing it in a low percentile for near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

Exploitation steps

  1. Prerequisite acquisition: Obtain a valid authentication provider token (e.g., via phishing, credential theft, or OAuth token theft) for the target Parse Server user account, along with at least one MFA recovery code or SMS OTP (e.g., via social engineering, SIM swapping, or prior access to the account's recovery codes).
  2. Identify the target endpoint: Confirm the Parse Server instance is running a vulnerable version (< 8.6.64 or 9.0.0–9.7.0-alpha.7) and locate the REST API login endpoint, typically POST /1/users.
  3. Craft the concurrent login payload: Construct a JSON request body using the authData field containing both the third-party provider credentials and the MFA recovery code, e.g.:
{
  "authData": {
    "fakeProvider": { "id": "user1", "token": "<stolen_token>" },
    "mfa": { "token": "<recovery_code>" }
  }
}
  1. Send concurrent requests: Use a tool such as curl with parallel execution, a script using Promise.allSettled in Node.js, or a load-testing tool (e.g., ab, wrk) to fire 10 or more identical requests simultaneously before any single request can consume the recovery code.
  2. Harvest sessions: Collect the session tokens from all successful responses. Due to the race condition, multiple requests will succeed and return valid session tokens before the recovery code is marked as consumed.
  3. Maintain persistence: Use the harvested session tokens to maintain access. Even if the legitimate user detects and revokes one session, the attacker retains access via the remaining sessions (GitHub Advisory, Patch PR #10326).

Indicators of compromise

  • Network: Multiple simultaneous POST requests to /1/users (or the configured Parse Server users endpoint) from the same source IP within milliseconds, all containing identical authData payloads including the same MFA recovery code or SMS OTP.
  • Logs: Parse Server access logs showing multiple successful 200 OK responses to concurrent POST /1/users requests using the same authentication provider token and MFA token within a very short time window; subsequent session activity from geographically or device-profile-disparate locations.
  • Application State: More active sessions associated with a single user account than expected; MFA recovery codes consumed without corresponding legitimate user login activity; user-reported unexpected session revocations or account access notifications.

Mitigation and workarounds

Upgrade Parse Server immediately to version 8.6.64 (for the 8.x LTS branch) or 9.7.0-alpha.8 or later (for the 9.x branch, with stable 9.7.0 also containing the fix) (GitHub Advisory, Patch PR #10327). The GitHub Advisory notes there is no known configuration-based workaround; however, as an interim measure, implementing rate limiting on the authData login endpoint to prevent concurrent authentication requests from the same token can reduce exploitation risk. Additionally, monitoring authentication logs for patterns of multiple session creation from the same MFA credential and enabling device fingerprinting or geographic anomaly detection can help identify suspicious activity until patching is complete.

Community reactions

The vulnerability was reported and patched by Parse Server maintainer mtrezza on March 26, 2026, with fixes simultaneously released for both the 8.x LTS and 9.x alpha branches (Patch PR #10326, Patch PR #10327). The fix was included in the stable Parse Server 9.7.0 release on March 30, 2026, alongside several other security fixes. No significant broader community or media commentary has been identified beyond the GitHub advisory and standard CVE tracking databases.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management