UNKNOWN npm
parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
GHSA-79wj-8rqv-jvp5 · BIT-parse-2026-30229 · CVE-2026-30229
Published · Modified
Description
Impact
The readOnlyMasterKey can call POST /loginAs to obtain a valid session token for any user. This allows a read-only credential to impersonate arbitrary users with full read and write access to their data. Any Parse Server deployment that uses readOnlyMasterKey is affected.
Patches
The fix adds a check to the /logInAs handler.
Workarounds
There is no workaround other than not using readOnlyMasterKey.
References
- GitHub security advisory: https://github.com/parse-community/parse-server/security/advisories/GHSA-79wj-8rqv-jvp5
- Fix for Parse Server 9: https://github.com/parse-community/parse-server/releases/tag/9.5.0-alpha.4
- Fix for Parse Server 8: https://github.com/parse-community/parse-server/releases/tag/8.6.6
References
- WEB https://github.com/parse-community/parse-server/security/advisories/GHSA-79wj-8rqv-jvp5
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-30229
- PACKAGE https://github.com/parse-community/parse-server
- WEB https://github.com/parse-community/parse-server/releases/tag/8.6.6
- WEB https://github.com/parse-community/parse-server/releases/tag/9.5.0-alpha.4
Ready to move
Start Securing
Free, no credit card | First findings in minutes