CVE-2026-30947: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-30947 is a class-level permissions (CLP) bypass vulnerability in Parse Server's LiveQuery feature, allowing unauthenticated or unauthorized clients to subscribe to restricted data streams and receive real-time object events. It affects all Parse Server (npm) versions prior to 8.6.16 and versions 9.0.0 through 9.5.2-alpha.2. The vulnerability was disclosed on March 10, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is CWE-863 (Incorrect Authorization): Parse Server fails to enforce class-level permissions when processing LiveQuery subscription requests. The LiveQuery subsystem, which provides real-time WebSocket-based data push, does not check CLP restrictions either at subscription creation time or during event delivery. An attacker with network access to the Parse Server LiveQuery endpoint can subscribe to any LiveQuery-enabled class without authentication or authorization, receiving all object-level events in real time. The fix, applied in versions 8.6.16 and 9.5.2-alpha.3, enforces CLP checks both before creating the subscription and during event delivery (Parse Server Advisory, GitHub Advisory).

Impact

Successful exploitation results in unauthorized real-time access to all objects within any LiveQuery-enabled class, regardless of the CLP restrictions configured by administrators. The confidentiality impact is high — sensitive data intended to be restricted (e.g., user records, private application data) is continuously streamed to unauthorized subscribers. There is no integrity or availability impact, and no evidence of lateral movement capability, but persistent passive data exfiltration is possible for as long as the subscription remains active (GitHub Advisory, Parse Server Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker against a vulnerable Parse Server instance with LiveQuery enabled. The EPSS score is approximately 0.013–0.019%, indicating a low current probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances with LiveQuery enabled (typically exposed via WebSocket on the configured LiveQuery port or path, e.g., ws://target/parse). Confirm the server version is below 8.6.16 or between 9.0.0 and 9.5.2-alpha.2.
  2. Identify target classes: Use the Parse Server REST API or SDK to enumerate available classes (some may be publicly listed depending on configuration), or target known class names common to Parse applications (e.g., _User, Post, Message).
  3. Establish LiveQuery WebSocket connection: Connect to the Parse Server LiveQuery endpoint using a WebSocket client or the Parse JavaScript SDK without providing valid session credentials.
  4. Send subscription message: Send a LiveQuery subscribe message for the target class without a valid session token, e.g.:
    {"op": "subscribe", "requestId": 1, "query": {"className": "PrivateData", "where": {}}}
  5. Receive real-time data: Due to the missing CLP enforcement, the server accepts the subscription and begins streaming all create, update, delete, and enter/leave events for objects in the class, exposing restricted data in real time (Parse Server Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or unauthenticated WebSocket connections to the Parse Server LiveQuery endpoint (e.g., ws://host/parse or configured LiveQuery URL); high-frequency or long-lived WebSocket sessions from unknown or external IP addresses.
  • Logs: Parse Server logs showing LiveQuery subscribe operations for CLP-restricted classes from sessions with no associated user or session token; repeated subscription attempts from the same IP across multiple classes.
  • Process/Application: Unusual volume of LiveQuery event deliveries logged server-side for classes that should have restricted access; absence of session token in LiveQuery subscription log entries for sensitive classes.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.16 (for the 8.x branch) or 9.5.2-alpha.3 (for the 9.x branch), which enforce CLP checks both at subscription creation and during event delivery (Parse Server 8.6.16 Release, Parse Server 9.5.2-alpha.3 Release). If immediate patching is not possible, disable LiveQuery for all classes that rely on CLP restrictions by removing them from the liveQuery.classNames server configuration option — this prevents unauthorized subscriptions to sensitive classes (Parse Server Advisory).

Community reactions

The vulnerability was reported and coordinated by maintainer mtrezza of the parse-community organization, who also published the security advisory on March 10, 2026 (Parse Server Advisory). No significant broader media coverage or notable external researcher commentary has been identified beyond the official advisory and standard CVE tracking databases.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management