Detects Parse Server instances where allowExpiredAuthDataToken is enabled and auth provider validation is skipped on login when authData matches stored data. An attacker who obtains stored authData can impersonate any user with linked OAuth accounts, gaining a valid session token without the provider re-validating credentials. Affects versions before 8.6.52 and 9.0.0 through 9.6.0-alpha.40.
Is your app exploitable through CVE-2026-33409?
Scan your domain free