CVE-2026-33624

LOW EPSS 7.2%
Published Mar 24, 20263mo ago · Modified Jun 17, 20262w ago
2.1 CVSS 4.0
Low
Find Similar
Published Mar 24, 2026 3mo ago
Last Modified Jun 17, 2026 2w ago

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that recovery code an unlimited number of times by sending concurrent login requests. This defeats the single-use design of recovery codes. The attack requires the user's password, a valid recovery code, and the ability to send concurrent requests within milliseconds. This issue has been patched in versions 8.6.60 and 9.6.0-alpha.54.

CVSS Details

Base Score
2.1
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity High
Privileges Required High
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
7.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-367

Affected Products 55

VendorProductVersionRange
parseplatformparse-server* <8.6.60
parseplatformparse-server*≥9.0.0  –  <9.6.0
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any
parseplatformparse-server9.6.0any

References 5

  • github.com https://github.com/parse-community/parse-server/commit/5e70094250a36bfcc14ecd49592be2b94fba66ff
    Patch
  • github.com https://github.com/parse-community/parse-server/commit/fc3da35a81d5083b453e8967cabcc880f1a3bd0c
    Patch
  • github.com https://github.com/parse-community/parse-server/pull/10275
    Issue Tracking
  • github.com https://github.com/parse-community/parse-server/pull/10276
    Issue Tracking
  • github.com https://github.com/parse-community/parse-server/security/advisories/GHSA-2299-ghjr-6vjp
    Vendor Advisory

Remediation

  • github.com https://github.com/parse-community/parse-server/commit/5e70094250a36bfcc14ecd49592be2b94fba66ff
    Patch
  • github.com https://github.com/parse-community/parse-server/commit/fc3da35a81d5083b453e8967cabcc880f1a3bd0c
    Patch