CVE-2026-31875: Parseplatform Parse-Server

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generates two single-use recovery codes. These codes are intended as a fallback when the user cannot provide a TOTP token. However, recovery codes are not consumed after use, allowing the same recovery code to be used an unlimited number of times. This defeats the single-use design of recovery codes and weakens the security of MFA-protected accounts. An attacker who obtains a single recovery code can repeatedly authenticate as the affected user without the code ever being invalidated. This vulnerability is fixed in 9.6.0-alpha.7 and 8.6.33.

Affected products

  • Parseplatform Parse-Server: before 8.6.33 (fixed in 8.6.33); from 9.0.0, before 9.6.0 (fixed in 9.6.0); version 9.6.0 only

Published 2026-03-11. Last modified 2026-06-17.