PT-2026-26760 · Unknown · Parse Server

·

CVE-2026-33429

·

Publicado

2026-03-20

·

Atualizado

2026-03-27

CVSS v4.0

6.3

Média

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 8.6.54 Parse Server versions prior to 9.6.0-alpha.43
Description Parse Server contains a flaw where an attacker can subscribe to LiveQuery using a watch parameter that targets a protected field. While the actual value of the protected field is removed from event payloads, the system reveals whether the field has been updated, creating a binary oracle. For boolean protected fields, the timing of these events can reveal the field’s value. The watch parameter is not validated against protected fields during subscription, allowing this information leakage. Master key connections are exempt from this issue.
Recommendations Update to Parse Server version 8.6.54 or later. Update to Parse Server version 9.6.0-alpha.43 or later.

Exploit

Correção

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-PARSE-2026-33429
CVE-2026-33429
GHSA-QPC3-FG4J-8HGM

Produtos afetados

Parse Server