CVE-2026-87806
Deferred Deferred - Pending Action

Authentication Bypass in Parse Server via LDAP Adapter

Vulnerability report for CVE-2026-87806, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter. The adapter forwarded the client-supplied password to the directory without verifying that a password had been supplied, and treated any non-error response from the directory as proof of authentication. A zero-length credential turns an LDAP simple bind into the unauthenticated authentication mechanism described in RFC 4513 section 5.1.2, which some directories (including Active Directory in its default configuration) answer with success while mapping the connection to anonymous. As a result, an unauthenticated attacker who knows a directory username can obtain a valid session token for that account, resulting in account takeover. Only deployments that enable the LDAP authentication adapter are affected, and deployments whose directory refuses unauthenticated simple bind (such as a stock OpenLDAP configuration) are not exploitable. The issue is fixed in 8.6.88 and 9.10.1-alpha.7, which require the password to be a non-empty string and reject the request before contacting the directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
parse server From 9.0.0 (inc) to 9.10.1-alpha.7 (exc)
parse server to 8.6.87 (inc)
parse server 8.6.88
parse server 9.10.1-alpha.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7. It is an authentication bypass in the built-in LDAP adapter where the server forwards a client-supplied password to the LDAP directory without checking if a password was provided. An empty password triggers an unauthenticated LDAP bind, which some directories like Active Directory accept as valid, allowing an attacker to obtain a valid session token for any account they know the username of.

Detection Guidance

To detect this vulnerability, check if your Parse Server version is vulnerable by running: npm list parse-server. If the version is <= 8.6.87 or >= 9.0.0 and < 9.10.1-alpha.7, it is affected. Additionally, verify if the LDAP authentication adapter is enabled in your Parse Server configuration.

Impact Analysis

An unauthenticated attacker could take over any account by exploiting this vulnerability, leading to unauthorized access to sensitive data, privilege escalation, or further attacks within the system. Only systems using the LDAP authentication adapter are affected.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, which may violate compliance requirements under GDPR (e.g., unauthorized data access under Article 32) and HIPAA (e.g., unauthorized access to protected health information under the Security Rule). The authentication bypass allows attackers to impersonate users, potentially exposing personal or health data.

Mitigation Strategies

Immediately upgrade to a patched version: 8.6.88 or 9.10.1-alpha.7 or later. If upgrading is not possible, disable the LDAP authentication adapter or configure your LDAP directory to reject unauthenticated binds. Ensure all passwords are non-empty strings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87806. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart