{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-87806/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:parseplatform:parse_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-87806"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Parse Server (\u003c= 8.6.87, \u003e= 9.0.0 \u003c 9.10.1-alpha.7)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve-2026-87806","account-takeover"],"_cs_type":"advisory","_cs_vendors":["Parse Platform"],"content_html":"\u003cp\u003eParse Server versions \u0026lt;= 8.6.87 and \u0026gt;= 9.0.0 \u0026lt; 9.10.1-alpha.7 contain a critical authentication bypass vulnerability (CVE-2026-87806) within the built-in LDAP authentication adapter. The vulnerability stems from improper input validation where the adapter fails to verify the presence of a user-supplied password before initiating a bind request to the directory. If an attacker submits a zero-length password, the application proceeds with an LDAP simple bind request. When integrated with directories that support unauthenticated simple binds, such as Active Directory in its default configuration, the directory treats this request as an anonymous bind and returns a success response. Parse Server interprets this success as a valid authentication event, resulting in the issuance of a session token for the target username. This allows unauthenticated attackers who possess knowledge of a valid directory username to gain unauthorized access to the application. This vulnerability does not affect deployments using directories that explicitly reject unauthenticated binds.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full account takeover, allowing attackers to access private user data, modify account configurations, or gain escalated privileges depending on the permissions associated with the targeted directory account. This affects any Parse Server deployment utilizing the affected LDAP authentication adapter in conjunction with permissive directory services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Parse Server instances to version 8.6.88 or 9.10.1-alpha.7 to ensure proper enforcement of non-empty password requirements.\u003c/li\u003e\n\u003cli\u003eAudit LDAP directory configurations to ensure they are configured to reject unauthenticated simple binds, which serves as a defense-in-depth measure against this class of vulnerability.\u003c/li\u003e\n\u003cli\u003eReview application logs for anomalous authentication patterns, specifically frequent successful logins associated with empty credentials or unexpected authentication source behavior.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T12:57:23Z","date_published":"2026-09-09T12:57:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-parse-server-auth-bypass/","summary":"Parse Server versions before 8.6.88 and 9.10.1-alpha.7 contain an authentication bypass vulnerability in the LDAP adapter that allows attackers to perform account takeover via zero-length credentials.","title":"Authentication Bypass in Parse Server LDAP Adapter (CVE-2026-87806)","url":"https://feed.craftedsignal.io/briefs/2026-09-parse-server-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-87806","version":"https://jsonfeed.org/version/1.1"}