PT-2026-99303 · Unknown · Parse Server
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Parse Server versions 9.0.0 through 9.10.1-alpha.7
Parse Server versions prior to 8.6.89
Description
LiveQuery evaluates the
protectedFields class-level permission using an incompletely resolved caller identity. Because subscriber roles are not resolved and subscriptions without a session token are redacted against an anonymous identity, field masks defined for specific roles, authenticated users, or individual users are not applied. This allows authenticated subscribers to receive field values that the REST API would normally withhold and enables the use of masked fields to filter or watch a subscription. This issue only affects classes with LiveQuery enabled that define protectedFields under role, authenticated, or per-user groups; masks under the public (*) group function correctly.Recommendations
Update versions 9.0.0 through 9.10.1-alpha.7 to version 9.10.1-alpha.8.
Update versions prior to 8.6.89 to version 8.6.89.
Define the affected field masks under the public (*) group.
Disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user
protectedFields groups.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parse Server