CVE-2026-32594 | parse-community parse-server up to 8.6.39/9.0.0 9.6.0-alpha.13 GraphQL WebSocket Endpoint missing authentication (EUVD-2026-12097)
A vulnerability was found in parse-community parse-server up to 8.6.39/9.0.0 9.6.0-alpha.13. It has been declared as critical. The impacted element is an unknown function of the component GraphQL WebSocket Endpoint. Executing a manipulation can lead to missing authentication.
This vulnerability appears as CVE-2026-32594. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.