Detects Parse Server instances where the authentication endpoint accepts non-string values in the authData user identifier field. An unauthenticated attacker can send a crafted login request that causes the server to perform a pattern-matching query instead of an exact-match lookup, matching any existing user and obtaining their session token. Anonymous authentication is enabled by default. Affects all versions before 8.6.38 and 9.0.0 through 9.6.0-alpha.11.
Is your app exploitable through CVE-2026-32248?
Scan your domain free