CVE-2026-30863 affects Parse Server prior to versions 8.6.10 and 9.5.0-alpha.11. The vulnerability is in the Google, Apple, and Facebook authentication adapters, which use JWT verification to validate identity tokens. When the adapter audience configuration is not set—clientId for Google and Apple, or appIds for Facebook—the JWT verification flow silently skips validation of the token's aud claim. As a result, a validly signed identity token issued by the provider for a different application can be accepted by the target Parse Server instance. This breaks the trust boundary between applications and can allow an attacker to authenticate as arbitrary users on the vulnerable Parse Server deployment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
clientId for Google and Apple. This reduces exposure by causing JWT audience claims to be validated. For Facebook Limited Login, the provided content states there is no effective workaround on vulnerable versions; the practical mitigation is to upgrade to a fixed release. More generally, disable affected social login adapters if they are not required until patching is completed.Patch, then assume compromise.
clientId mandatory for Google and Apple adapters and appIds mandatory for Facebook, and ensures those values are passed into JWT audience validation so the aud claim is enforced.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.