Field Mask Disclosure in Parse Server by Parse Community
CVE-2026-100632

7.1HIGH

Key Information:

Vendor
CVE Published:
26 September 2026

What is CVE-2026-100632?

Parse Server, an open-source backend server, has a vulnerability affecting versions 9.0.0 through 9.10.1-alpha.8, and versions earlier than 8.6.89. The issue arises when LiveQuery evaluates class-level permissions without completely resolving the caller's identity. Specifically, the system fails to accurately assess subscriber roles when a session token is absent, leading to potential unauthorized access to protected fields. Consequently, authenticated users may retrieve field values that should be restricted, as the REST API appropriately masks them. This vulnerability primarily impacts classes employing LiveQuery with defined protectedFields under specific roles such as authenticated or per-user groups. To mitigate the risk, users are advised to update to version 9.10.1-alpha.8 or 8.6.89 or adopt workarounds by ensuring affected field masks are defined publicly or disabling LiveQuery for specific classes.

Affected Version(s)

parse-server 9.0.0 < 9.10.1-alpha.8

parse-server 0 < 8.6.89

parse-server 9.10.1-alpha.8

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d3do-23
mtrezza
.