A vulnerability marked as problematic has been reported in parse-community parse-server up to 8.6.38/9.6.0-alpha.12. This affects an unknown part of the component Token Introspection Endpoint. Performing a manipulation results in function call with incorrect order of arguments.

This vulnerability is identified as CVE-2026-32269. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.