PT-2026-99303 · Unknown · Parse Server

·

CVE-2026-100632

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions 9.0.0 through 9.10.1-alpha.7 Parse Server versions prior to 8.6.89
Description LiveQuery evaluates the protectedFields class-level permission using an incompletely resolved caller identity. Because subscriber roles are not resolved and subscriptions without a session token are redacted against an anonymous identity, field masks defined for specific roles, authenticated users, or individual users are not applied. This allows authenticated subscribers to receive field values that the REST API would normally withhold and enables the use of masked fields to filter or watch a subscription. This issue only affects classes with LiveQuery enabled that define protectedFields under role, authenticated, or per-user groups; masks under the public (*) group function correctly.
Recommendations Update versions 9.0.0 through 9.10.1-alpha.7 to version 9.10.1-alpha.8. Update versions prior to 8.6.89 to version 8.6.89. Define the affected field masks under the public (*) group. Disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user protectedFields groups.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100632
GHSA-9JPP-XHH6-75MF

Affected Products

Parse Server