
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30947 is a class-level permissions (CLP) bypass vulnerability in Parse Server's LiveQuery feature, allowing unauthenticated or unauthorized clients to subscribe to restricted data streams and receive real-time object events. It affects all Parse Server (npm) versions prior to 8.6.16 and versions 9.0.0 through 9.5.2-alpha.2. The vulnerability was disclosed on March 10, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Parse Server Advisory).
The root cause is CWE-863 (Incorrect Authorization): Parse Server fails to enforce class-level permissions when processing LiveQuery subscription requests. The LiveQuery subsystem, which provides real-time WebSocket-based data push, does not check CLP restrictions either at subscription creation time or during event delivery. An attacker with network access to the Parse Server LiveQuery endpoint can subscribe to any LiveQuery-enabled class without authentication or authorization, receiving all object-level events in real time. The fix, applied in versions 8.6.16 and 9.5.2-alpha.3, enforces CLP checks both before creating the subscription and during event delivery (Parse Server Advisory, GitHub Advisory).
Successful exploitation results in unauthorized real-time access to all objects within any LiveQuery-enabled class, regardless of the CLP restrictions configured by administrators. The confidentiality impact is high — sensitive data intended to be restricted (e.g., user records, private application data) is continuously streamed to unauthorized subscribers. There is no integrity or availability impact, and no evidence of lateral movement capability, but persistent passive data exfiltration is possible for as long as the subscription remains active (GitHub Advisory, Parse Server Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker against a vulnerable Parse Server instance with LiveQuery enabled. The EPSS score is approximately 0.013–0.019%, indicating a low current probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported.
ws://target/parse). Confirm the server version is below 8.6.16 or between 9.0.0 and 9.5.2-alpha.2._User, Post, Message).subscribe message for the target class without a valid session token, e.g.:{"op": "subscribe", "requestId": 1, "query": {"className": "PrivateData", "where": {}}}create, update, delete, and enter/leave events for objects in the class, exposing restricted data in real time (Parse Server Advisory, GitHub Advisory).ws://host/parse or configured LiveQuery URL); high-frequency or long-lived WebSocket sessions from unknown or external IP addresses.subscribe operations for CLP-restricted classes from sessions with no associated user or session token; repeated subscription attempts from the same IP across multiple classes.Upgrade Parse Server to version 8.6.16 (for the 8.x branch) or 9.5.2-alpha.3 (for the 9.x branch), which enforce CLP checks both at subscription creation and during event delivery (Parse Server 8.6.16 Release, Parse Server 9.5.2-alpha.3 Release). If immediate patching is not possible, disable LiveQuery for all classes that rely on CLP restrictions by removing them from the liveQuery.classNames server configuration option — this prevents unauthorized subscriptions to sensitive classes (Parse Server Advisory).
The vulnerability was reported and coordinated by maintainer mtrezza of the parse-community organization, who also published the security advisory on March 10, 2026 (Parse Server Advisory). No significant broader media coverage or notable external researcher commentary has been identified beyond the official advisory and standard CVE tracking databases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."