PT-2026-61927 · Unknown · Parse Server

·

CVE-2026-64627

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Parse Server versions 9.0.0 through 9.10.0-alpha.3 Parse Server versions prior to 8.6.85
Description A schema disclosure issue exists when the GraphQL API is configured with graphQLPublicIntrospection set to false. Error messages generated during variable coercion continue to provide schema-derived suggestions, bypassing the introspection-hardening control. An unauthenticated user with the public application id can iteratively recover hidden schema identifiers, such as Parse class and field names and registered Cloud Code function names, by submitting queries or mutations with near-miss enum values or input-object field names.
Recommendations Update to version 9.10.0-alpha.4 or later. Update to version 8.6.85 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64627
GHSA-9G8F-H8F3-HJCM

Affected Products

Parse Server