Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100632— Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery

Quick assessment

Affected
parse-community parse-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Parse Server 是一个开源的后端服务器。在版本 >= 9.0.0 且 < 9.10.1-alpha.8,以及版本 < 8.6.89 中,LiveQuery 在处理 类级别权限时,对调用者身份识别存在不完整解析的问题:订阅者(subscriber)的角色信息未被正确解析;当订阅未提供自身的 session token 时,事件载荷会基于匿名身份进行字段裁剪(redacted),尽管该读取操作实际上已针对已连接的认证用户授权。因此,针对角色、认证用户或特定用户定义的字段掩码(field masks)未被正确应

CVSS 6.5 · Medium EPSS 0.29% · P20
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100632

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery
Source: CVE Program / CVE List V5
Vulnerability Description
Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own session token the event payload is redacted against an anonymous identity even though the read was authorized against the connected user. As a result, field masks defined for a role, for authenticated users, or for a specific user are not applied, so an authenticated subscriber can receive field values that the REST API correctly withholds and can use a masked field to filter or watch a subscription. Only classes with LiveQuery enabled that define protectedFields under a role:, authenticated, or per-user group are affected; masks under the public (*) group are applied correctly. The issue is fixed in 9.10.1-alpha.8 and 8.6.89. As a workaround, additionally define the affected field masks under the public (*) group, or disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user protectedFields groups.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
parse-community parse-server 9.0.0 ~ 9.10.1-alpha.8 -
parse-community parse-server 0 ~ 8.6.89 -

II. Public POCs for CVE-2026-100632

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100632

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100632 (1)

Other References for CVE-2026-100632 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100632

No comments yet


Leave a comment