All verified exploits

CVE-2026-32248 Account Takeover via Operator Injection in Authentication Data

Deterministic critical Parse Server Added cve-verified-cve-2026-32248

Detects Parse Server instances where the authentication endpoint accepts non-string values in the authData user identifier field. An unauthenticated attacker can send a crafted login request that causes the server to perform a pattern-matching query instead of an exact-match lookup, matching any existing user and obtaining their session token. Anonymous authentication is enabled by default. Affects all versions before 8.6.38 and 9.0.0 through 9.6.0-alpha.11.

Is your app exploitable through CVE-2026-32248?

Scan your domain free