
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31872 is a protected fields bypass vulnerability in Parse Server, an open-source Node.js backend platform, that allows unauthenticated remote attackers to enumerate values of fields protected by class-level permissions (CLP). The vulnerability was disclosed on March 10, 2026, and affects Parse Server versions prior to 8.6.32 and versions 9.0.0 through 9.6.0-alpha.5. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Parse Server Advisory).
The root cause is improper access control (CWE-284) in how Parse Server evaluates query WHERE clause keys and sort parameters against protectedFields CLP configurations. When a field such as secretObj is marked as protected, the server failed to strip dot-notation sub-paths (e.g., secretObj.apiKey) before checking against the protected fields list, allowing the sub-field reference to bypass the restriction entirely. This flaw affects both MongoDB and PostgreSQL database backends. The fix, applied in the patched releases, extracts the root field name from any dot-notation path before performing the protected fields check, so a query on secretObj.apiKey is now correctly blocked when secretObj is protected (Parse Server Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to conduct a binary oracle attack — iteratively querying or sorting by sub-fields of a protected object field to infer its values character by character or through conditional responses. This results in a high confidentiality impact, as sensitive data stored in protected fields (e.g., API keys, tokens, or personal information) can be enumerated without authorization. There is no integrity or availability impact, and the vulnerability is scoped to the vulnerable Parse Server instance itself without lateral movement to subsequent systems (Parse Server Advisory, GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable against any exposed Parse Server instance running a vulnerable version. The EPSS score is approximately 0.049% (16th percentile), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
protectedFields in the CLP.secretObj.apiKey with a specific value guess (e.g., {"where": {"secretObj.apiKey": {"$gt": "m"}}})./parse/classes/<ClassName>) from a single IP or user agent, particularly with repetitive WHERE clause patterns targeting the same field with incrementally varying values.secretObj.apiKey, protectedField.subfield) in WHERE or sort parameters, especially with comparison operators like $gt, $lt, or $regex.protectedFields in the class-level permissions schema.Parse Server has released patched versions addressing this vulnerability: 8.6.32 for the stable branch and 9.6.0-alpha.6 for the alpha branch, both released on March 10, 2026. There are no known workarounds — upgrading to a patched version is the only remediation. Administrators should also audit their protectedFields CLP configurations and monitor query logs for suspicious dot-notation access patterns as a defense-in-depth measure (Parse Server 8.6.32 Release, Parse Server 9.6.0-alpha.6 Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."