CVE-2026-53726 | parse-community parse-server up to 8.6.79/9.9.1-alpha.5 Private Group relatedTo authorization (GHSA-wmwx-jr2p-4j4r)

SecurityVulns

A vulnerability was found in parse-community parse-server up to 8.6.79/9.9.1-alpha.5. It has been rated as problematic. This issue affects some unknown processing of the component Private Group Handler. Performing a manipulation of the argument relatedTo results in authorization bypass.

This vulnerability is identified as CVE-2026-53726. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More