Algorithm Confusion: Critical 9.1 Flaw in Parse Server Allows Instant Google Account Takeover
ID: 18a0fdc2-09f4-598f-8442-d59ab6020c27
STIX ID: report--18a0fdc2-09f4-598f-8442-d59ab6020c27
Feed Name: securityonline.info
Executive summary: Parse Server has a critical algorithm‑confusion vulnerability (CVE-2026-27804, CVSSv4 9.1) in its Google authentication adapter that allows an unauthenticated attacker to forge Google JWTs by setting alg:"none", enabling full account takeover of Google-linked users. Affected versions are >=9.0.0 <=9.3.1-alpha.3 and <=8.6.2; patched releases are 9.3.1-alpha.4 and 8.6.3. The fix hardcodes RS256 and replaces the custom key fetcher with jwks-rsa; administrators should apply patches immediately or disable Google authentication until upgraded.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
