Schema Disclosure Vulnerability in Parse Server by Parse Community
CVE-2026-64627

6.9MEDIUM

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-64627?

A schema disclosure vulnerability exists in Parse Server affecting versions prior to 9.10.0-alpha.4 and 8.6.85. This issue allows unauthenticated users to exploit the GraphQL API, returning hidden schema identifiers such as Cloud Code function names and Parse class and field names. When public introspection is disabled, the system still presents schema-derived suggestions in error messages, which can be manipulated by an attacker to iteratively uncover sensitive information. This security flaw represents a bypass to prior safeguards (GHSA-8cph-rgr4-g5vj) and poses significant risks to information confidentiality.

Affected Version(s)

parse-server 9.0.0 < 9.10.0-alpha.4

parse-server 0 < 8.6.85

parse-server 9.10.0-alpha.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
mtrezza
.