Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-87806

Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password
Back to all
CVE

CVE-2026-87806

Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter. The adapter forwarded the client-supplied password to the directory without verifying that a password had been supplied, and treated any non-error response from the directory as proof of authentication. A zero-length credential turns an LDAP simple bind into the unauthenticated authentication mechanism described in RFC 4513 section 5.1.2, which some directories (including Active Directory in its default configuration) answer with success while mapping the connection to anonymous. As a result, an unauthenticated attacker who knows a directory username can obtain a valid session token for that account, resulting in account takeover. Only deployments that enable the LDAP authentication adapter are affected, and deployments whose directory refuses unauthenticated simple bind (such as a stock OpenLDAP configuration) are not exploitable. The issue is fixed in 8.6.88 and 9.10.1-alpha.7, which require the password to be a non-empty string and reject the request before contacting the directory.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
7.4
-
3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87806.json, https://github.com/parse-community/parse-server/security/advisories/GHSA-863r-39r9-vfcf, https://nvd.nist.gov/vuln/detail/CVE-2026-87806, https://www.vulncheck.com/advisories/parse-server-9.0.0-authentication-bypass-via-ldap-empty-password

Severity

7.4

CVSS Score
0
10

Basic Information

Base CVSS
7.4
EPSS Probability
0.00511%
EPSS Percentile
0.41739%
Introduced Version
0,9.0.0,3.10.0
Fix Available
8dd19d751a913bcb39f69895732e73b18b49c851,9.10.1-alpha.7,8.6.88

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading