Schema Disclosure Vulnerability in Parse Server by Parse Community
CVE-2026-64627
6.9MEDIUM
What is CVE-2026-64627?
A schema disclosure vulnerability exists in Parse Server affecting versions prior to 9.10.0-alpha.4 and 8.6.85. This issue allows unauthenticated users to exploit the GraphQL API, returning hidden schema identifiers such as Cloud Code function names and Parse class and field names. When public introspection is disabled, the system still presents schema-derived suggestions in error messages, which can be manipulated by an attacker to iteratively uncover sensitive information. This security flaw represents a bypass to prior safeguards (GHSA-8cph-rgr4-g5vj) and poses significant risks to information confidentiality.
Affected Version(s)
parse-server 9.0.0 < 9.10.0-alpha.4
parse-server 0 < 8.6.85
parse-server 9.10.0-alpha.4
