#VU124967 Insufficient verification of data authenticity in Parse Server - CVE-2026-27804
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to log in as any user linked to a Google account.
The vulnerability exists due to insufficient verification of data authenticity in the Google auth adapter when processing forged Google authentication tokens. A remote attacker can forge a token with alg set to none to log in as any user linked to a Google account.
Only deployments with Google authentication enabled are vulnerable.