CVE-2026-32943 | parse-community parse-server up to 8.6.47/9.6.0-alpha.27 Password Reset Token toctou (GHSA-r3xq-68wh-gwvh / EUVD-2026-12991)
A vulnerability labeled as problematic has been found in parse-community parse-server up to 8.6.47/9.6.0-alpha.27. Impacted is an unknown function of the component Password Reset Token Handler. Such manipulation leads to time-of-check time-of-use.
This vulnerability is referenced as CVE-2026-32943. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.