
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31840 is a critical SQL injection vulnerability in Parse Server (npm package parse-server by Parse Platform) that allows unauthenticated remote attackers to inject arbitrary SQL into a PostgreSQL database via improperly escaped dot-notation field names in query parameters. The vulnerability was published on March 10, 2026, and affects all Parse Server versions before 8.6.28 and versions 9.0.0 through 9.6.0-alpha.1 (i.e., before 9.6.0-alpha.2). It exclusively impacts deployments backed by a PostgreSQL database; MongoDB-backed deployments are not affected. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, Parse Server Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), specifically an insufficient escaping of sub-field values when dot-notation field names are processed in PostgreSQL query generation. When Parse Server constructs SQL queries using dot-notation (e.g., object.subfield), it fails to properly escape special characters in the sub-field portion, allowing an attacker to break out of the intended SQL context. The injection is triggerable via the sort, distinct, and where query parameters in Parse Server's REST API or SDK query interface — all without requiring authentication or user interaction. The fix, applied in versions 8.6.28 and 9.6.0-alpha.2, escapes characters in dot-notation sub-field values that could allow a SQL breakout (GitHub Advisory, Parse Server Advisory).
Successful exploitation grants an unauthenticated attacker full control over the PostgreSQL database backing the Parse Server instance, with high impact to confidentiality, integrity, and availability. An attacker could exfiltrate all stored application data (user records, credentials, application state), modify or delete database records, and potentially disrupt service availability through destructive SQL operations. Depending on PostgreSQL configuration and privileges granted to the Parse Server database user, exploitation could also enable OS-level command execution via PostgreSQL extensions (e.g., COPY TO/FROM PROGRAM), enabling lateral movement beyond the database (GitHub Advisory, Feedly).
As of the time of reporting, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability requires no authentication, no user interaction, and no special preconditions beyond the target running Parse Server with a PostgreSQL backend, making it highly automatable if a PoC were to emerge. The EPSS score is approximately 0.045% (22nd percentile), indicating a currently low but non-negligible probability of exploitation within 30 days (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/parse/classes/) can help enumerate targets. Confirm the backend is PostgreSQL by observing error messages or response behavior.GET /parse/classes/SomeClass) that includes a sort (or distinct or where) query parameter using a dot-notation field name with embedded SQL injection payload in the sub-field portion. For example: ?order=field.sub'-- or a more complex payload designed to break out of the SQL string context.UNION SELECT, time-based blind injection, or stacked queries depending on context).COPY TO PROGRAM for further system compromise (GitHub Advisory, Parse Server Advisory)./parse/classes/*) containing order, sort, distinct, or where parameters with SQL metacharacters (', --, ;, UNION, SELECT) in dot-notation field values; high volume of query requests from a single IP targeting these parameters.pg_log) containing malformed or anomalous SQL statements originating from the Parse Server database user.COPY TO PROGRAM or pg_read_file calls in PostgreSQL audit logs if superuser access was achieved.Parse Platform has released patched versions addressing this vulnerability: Parse Server 8.6.28 and Parse Server 9.6.0-alpha.2, both released on March 9–10, 2026. Administrators should upgrade immediately to one of these versions (Parse Server 8.6.28 Release, Parse Server 9.6.0-alpha.2 Release). There is no known workaround — the vendor explicitly states no workaround exists, so patching is the only remediation (GitHub Advisory). As interim measures until patching is complete, operators should implement network-level access controls to restrict Parse Server API access to trusted clients only, and enable PostgreSQL query logging to monitor for anomalous SQL patterns.
The vulnerability was reported and coordinated by mtrezza, a maintainer of the parse-community/parse-server project, who also served as the coordinator for the advisory (Parse Server Advisory). The advisory was published directly by the Parse Platform maintainers on March 10, 2026, with patches released simultaneously. No significant broader media coverage or notable external researcher commentary has been identified beyond standard CVE aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."