CVE-2026-30966 | parse-community parse-server up to 8.6.19/9.0.0 9.5.2-alpha.6 Delete Record access control (GHSA-5f92-jrq3-28rc)
A vulnerability classified as critical has been found in parse-community parse-server up to 8.6.19/9.0.0 9.5.2-alpha.6. This affects an unknown function of the component Delete Record Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-30966. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.