CVE-2026-34215
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-a
CVSS
6.5
Medio
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 31 mar 2026 · Última mod.: 24 jul 2026 · CWE-200
0.3%EPSS · 30 días0.3%
2026-08-122026-09-09
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP secrets, recovery codes, and OAuth access tokens. An attacker who knows a user's password can extract the MFA secret to generate valid MFA codes, defeating multi-factor authentication protection. This issue has been patched in versions 8.6.63 and 9.7.0-alpha.7.
- github.comhttps://github.com/parse-community/parse-server/commit/770be8647424d92f5425c41fa81065ffbbb171ed
- github.comhttps://github.com/parse-community/parse-server/commit/a1d4e7b12a12f16d3870dbee582a36765858e94c
- github.comhttps://github.com/parse-community/parse-server/pull/10323
- github.comhttps://github.com/parse-community/parse-server/pull/10324
- github.comhttps://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-867675.0 MED—
——0Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can retrieve cross-tenant data including requested asset names, requester display names and profile links, locations, and expected check-in dates without parameter manipulation.1dCVE-2026-878205.3 MED—
——0CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks.1dCVE-2026-878105.3 MED—
——0Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in hidden or unpublished documents and determine the number of matching blocks and pages.1dCVE-2026-842225.3 MED4.1%
——1The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones.1dCVE-2026-810225.3 MED4.1%
——1The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.1dCVE-2026-810215.3 MED4.1%
——1The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachment download paths, allowing unauthenticated attackers to read protected customer-uploaded attachments by enumerating sequential attachment identifiers.1d