Parse Server's custom object ID allows to acquire role privileges (CVE-2024-47183)
Parse Server versions prior to 7.3.0 with the option allowCustomObjectId set to true are vulnerable to a privilege escalation issue. An attacker who can create a new user can specify a custom object ID that allows them to acquire the privileges of a specific role. This vulnerability has been fixed in versions 6.5.9 and 7.3.0.
AI Analysis
Technical Summary
Parse Server is an open source backend platform running on Node.js. When the configuration option allowCustomObjectId is enabled, it allows attackers with user creation permissions to specify a custom object ID for new users. This can be exploited to escalate privileges by acquiring the rights associated with a particular role. The vulnerability is addressed in Parse Server versions 6.5.9 and 7.3.0.
Potential Impact
An attacker with the ability to create new users can escalate their privileges by setting a custom object ID, thereby gaining unauthorized role privileges. This could lead to unauthorized access and actions within the Parse Server environment.
Mitigation Recommendations
Upgrade Parse Server to version 6.5.9 or later, or 7.3.0 or later, where this vulnerability is fixed. Disabling the allowCustomObjectId option if not required can also mitigate the risk.
Parse Server's custom object ID allows to acquire role privileges (CVE-2024-47183)
Description
Parse Server versions prior to 7.3.0 with the option allowCustomObjectId set to true are vulnerable to a privilege escalation issue. An attacker who can create a new user can specify a custom object ID that allows them to acquire the privileges of a specific role. This vulnerability has been fixed in versions 6.5.9 and 7.3.0.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Parse Server is an open source backend platform running on Node.js. When the configuration option allowCustomObjectId is enabled, it allows attackers with user creation permissions to specify a custom object ID for new users. This can be exploited to escalate privileges by acquiring the rights associated with a particular role. The vulnerability is addressed in Parse Server versions 6.5.9 and 7.3.0.
Potential Impact
An attacker with the ability to create new users can escalate their privileges by setting a custom object ID, thereby gaining unauthorized role privileges. This could lead to unauthorized access and actions within the Parse Server environment.
Mitigation Recommendations
Upgrade Parse Server to version 6.5.9 or later, or 7.3.0 or later, where this vulnerability is fixed. Disabling the allowCustomObjectId option if not required can also mitigate the risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-parse-2024-47183
- Osv Schema Version
- 1.5.0
- Aliases
- ["CVE-2024-47183"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- High
Patch Information
Threat ID: 6aa005f2acd9273b49ab6316
Added to database: 09/08/2026, 12:56:18 UTC
Last enriched: 09/08/2026, 13:30:38 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.