CVE-2026-32098: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-32098 is an information disclosure vulnerability in Parse Server, an open-source Node.js backend platform, that allows unauthenticated attackers to infer the values of protected fields via LiveQuery subscription WHERE clauses. By crafting subscriptions that reference protected fields (including via dot-notation or $regex), an attacker can observe whether LiveQuery events are delivered for matching objects, creating a boolean oracle that leaks field values. The vulnerability affects all Parse Server versions prior to 8.6.35 and versions 9.0.0 through 9.6.0-alpha.8. It was published on March 10–11, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 6.9 (Medium) (Github Advisory, Parse Server Advisory).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Parse Server's LiveQuery feature failed to validate subscription WHERE clauses against the class's configured protectedFields in Class-Level Permissions (CLP), unlike the existing REST API which performs this validation. An attacker exploits this by establishing a WebSocket-based LiveQuery subscription with a WHERE clause that filters on a protected field — using direct field references, dot-notation for nested fields, or operators like $regex, $or, $and, or $nor — and then observing whether real-time events are delivered, effectively using the presence or absence of events as a binary signal to enumerate field values. No authentication is required, and the attack is network-accessible with low complexity. The fix adds WHERE clause validation at subscription creation time, mirroring the REST API's existing protectedFields enforcement (Parse Server Advisory, Github Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to systematically infer the values of fields that administrators have explicitly designated as protected via Class-Level Permissions. The impact is limited to confidentiality — there is no integrity or availability impact — but the boolean oracle technique can be used iteratively (e.g., with $regex patterns) to reconstruct full field values character by character. Any Parse Server class that simultaneously has protectedFields configured and LiveQuery enabled is at risk, potentially exposing sensitive data such as user credentials, tokens, or private application data (Parse Server Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.052% (16th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify Parse Server instances with LiveQuery enabled and determine which classes have protectedFields configured in their Class-Level Permissions. This may be inferred from application behavior or API responses.
  2. Establish LiveQuery connection: Connect to the Parse Server LiveQuery WebSocket endpoint (typically wss://<host>/1/events or similar) using the Parse SDK or a raw WebSocket client.
  3. Craft a probing subscription: Subscribe to a target class with a WHERE clause referencing a suspected protected field and a specific test value, e.g., { "where": { "sensitiveField": { "$regex": "^a" } } }.
  4. Observe event delivery: Monitor whether LiveQuery events (create/update/enter) are delivered for objects matching the WHERE clause. Event delivery indicates the protected field value matches the filter; no delivery indicates it does not.
  5. Iterate to enumerate values: Repeat step 3–4 with progressively refined $regex patterns or exact value guesses to reconstruct the full value of the protected field through binary search or character-by-character enumeration.
  6. Exfiltrate inferred data: Compile the inferred field values for further use, such as credential stuffing, targeted attacks, or data harvesting (Parse Server Advisory).

Indicators of compromise

  • Network: High volume of WebSocket connections to the Parse Server LiveQuery endpoint from a single IP or small IP range; repeated subscription/unsubscription cycles with systematically varying WHERE clause values targeting the same class.
  • Logs: Parse Server access logs showing numerous LiveQuery subscription requests with WHERE clauses referencing fields that are configured as protectedFields; patterns of $regex queries with incrementally changing patterns against a single field.
  • Application Behavior: Unusual spikes in LiveQuery subscription activity on classes with sensitive protected fields, particularly from unauthenticated sessions.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.35 (for the 8.x branch) or 9.6.0-alpha.9 (for the 9.x branch), both released on March 10, 2026, which add WHERE clause validation against protected fields at subscription creation time (Parse Server 8.6.35 Release, Parse Server 9.6.0-alpha.9 Release). For deployments that cannot be immediately patched, the recommended workarounds are: (1) disable LiveQuery for any class that has protectedFields configured in its Class-Level Permissions, or (2) remove protectedFields restrictions from classes that require LiveQuery functionality. Reviewing and auditing CLP configurations to minimize the intersection of LiveQuery-enabled and protectedFields-configured classes is also advisable (Parse Server Advisory).

Community reactions

The vulnerability was reported and coordinated by mtrezza, a Parse Server maintainer, and disclosed via GitHub Security Advisories on March 10, 2026. The advisory was noted on Bluesky by CVE tracking accounts and security news aggregators shortly after publication. No significant independent researcher commentary or major media coverage has been identified beyond standard CVE tracking and aggregator sites.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management