CVE-2026-30850 | parse-community parse-server up to 8.6.8/9.5.0-alpha.8 File Metadata Endpoint :filename authorization (EUVD-2026-10170)
A vulnerability described as problematic has been identified in parse-community parse-server up to 8.6.8/9.5.0-alpha.8. Affected by this vulnerability is an unknown functionality of the file /files/:appId/metadata/:filename of the component File Metadata Endpoint. Executing a manipulation can lead to missing authorization.
This vulnerability is registered as CVE-2026-30850. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.