๐Ÿ” CVE Alert

CVE-2026-100632

MEDIUM 6.5

Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own session token the event payload is redacted against an anonymous identity even though the read was authorized against the connected user. As a result, field masks defined for a role, for authenticated users, or for a specific user are not applied, so an authenticated subscriber can receive field values that the REST API correctly withholds and can use a masked field to filter or watch a subscription. Only classes with LiveQuery enabled that define protectedFields under a role:, authenticated, or per-user group are affected; masks under the public (*) group are applied correctly. The issue is fixed in 9.10.1-alpha.8 and 8.6.89. As a workaround, additionally define the affected field masks under the public (*) group, or disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user protectedFields groups.

CWE CWE-200
Vendor parse-community
Product parse-server
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for parse-community parse-server

Be the first to know when new medium vulnerabilities affecting parse-community parse-server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

parse-community / parse-server
9.0.0 < 9.10.1-alpha.8
parse-community / parse-server
0 < 8.6.89

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/parse-community/parse-server/security/advisories/GHSA-9jpp-xhh6-75mf vulncheck.com: https://www.vulncheck.com/advisories/parse-server-9.0.0-before-9.10.1-protected-fields-disclosure-via-livequery

Credits

๐Ÿ” d3do-23 mtrezza