Field Mask Disclosure in Parse Server by Parse Community
CVE-2026-100632
What is CVE-2026-100632?
Parse Server, an open-source backend server, has a vulnerability affecting versions 9.0.0 through 9.10.1-alpha.8, and versions earlier than 8.6.89. The issue arises when LiveQuery evaluates class-level permissions without completely resolving the caller's identity. Specifically, the system fails to accurately assess subscriber roles when a session token is absent, leading to potential unauthorized access to protected fields. Consequently, authenticated users may retrieve field values that should be restricted, as the REST API appropriately masks them. This vulnerability primarily impacts classes employing LiveQuery with defined protectedFields under specific roles such as authenticated or per-user groups. To mitigate the risk, users are advised to update to version 9.10.1-alpha.8 or 8.6.89 or adopt workarounds by ensuring affected field masks are defined publicly or disabling LiveQuery for specific classes.
Affected Version(s)
parse-server 9.0.0 < 9.10.1-alpha.8
parse-server 0 < 8.6.89
parse-server 9.10.1-alpha.8
