CVE-2026-34574

EUVD-2026-17502
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the session update endpoint. This allows nullifying the session expiry, making the session valid indefinitely and bypassing configured session length policies. This issue has been patched in versions 8.6.69 and 9.7.0-alpha.14.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
parseplatformparse-server
𝑥
< 8.6.69
parseplatformparse-server
9.0.0 ≤
𝑥
< 9.7.0
parseplatformparse-server
9.7.0:alpha1
parseplatformparse-server
9.7.0:alpha10
parseplatformparse-server
9.7.0:alpha11
parseplatformparse-server
9.7.0:alpha12
parseplatformparse-server
9.7.0:alpha13
parseplatformparse-server
9.7.0:alpha2
parseplatformparse-server
9.7.0:alpha3
parseplatformparse-server
9.7.0:alpha4
parseplatformparse-server
9.7.0:alpha5
parseplatformparse-server
9.7.0:alpha6
parseplatformparse-server
9.7.0:alpha7
parseplatformparse-server
9.7.0:alpha8
parseplatformparse-server
9.7.0:alpha9
𝑥
= Vulnerable software versions