CVE-2026-34574Parseplatform · Parse-server
Vulnerability data via NVD (ingested)
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the session update endpoint. This allows nullifying the session expiry, making the session valid indefinitely and bypassing configured session length policies. This issue has been patched in versions 8.6.69 and 9.7.0-alpha.14.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-34574product:"Parseplatform Parse-server"http.html:"Parse-server"More intel sources (5)
vuln:CVE-2026-34574vulnerabilities.cve_id: CVE-2026-34574CVE-2026-34574CVE-2026-34574"CVE-2026-34574" exploit -site:nvd.nist.gov