PT-2026-64286 · Unknown · Parse Server

·

CVE-2026-66009

·

Published

2026-07-24

·

Updated

2026-07-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions 9.0.0 through 9.10.0-alpha.4 Parse Server versions 8.2.2 through 8.6.85
Description GraphQL validation error messages reveal the names of required custom input fields even when public introspection is disabled via the graphQLPublicIntrospection variable. An attacker possessing only the public application id can trigger these errors to discover required non-null custom fields on classes they already reference by name. This behavior partially undermines the intent of hiding the schema. No stored data, credentials, optional field names, unreferenced class names, or Cloud Code function names are exposed.
Recommendations Update Parse Server to version 9.10.0-alpha.5 or later. Update Parse Server to version 8.6.86 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66009
GHSA-2FGH-8J2G-W354

Affected Products

Parse Server