
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32098 is an information disclosure vulnerability in Parse Server, an open-source Node.js backend platform, that allows unauthenticated attackers to infer the values of protected fields via LiveQuery subscription WHERE clauses. By crafting subscriptions that reference protected fields (including via dot-notation or $regex), an attacker can observe whether LiveQuery events are delivered for matching objects, creating a boolean oracle that leaks field values. The vulnerability affects all Parse Server versions prior to 8.6.35 and versions 9.0.0 through 9.6.0-alpha.8. It was published on March 10–11, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 6.9 (Medium) (Github Advisory, Parse Server Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Parse Server's LiveQuery feature failed to validate subscription WHERE clauses against the class's configured protectedFields in Class-Level Permissions (CLP), unlike the existing REST API which performs this validation. An attacker exploits this by establishing a WebSocket-based LiveQuery subscription with a WHERE clause that filters on a protected field — using direct field references, dot-notation for nested fields, or operators like $regex, $or, $and, or $nor — and then observing whether real-time events are delivered, effectively using the presence or absence of events as a binary signal to enumerate field values. No authentication is required, and the attack is network-accessible with low complexity. The fix adds WHERE clause validation at subscription creation time, mirroring the REST API's existing protectedFields enforcement (Parse Server Advisory, Github Advisory).
Successful exploitation allows an unauthenticated remote attacker to systematically infer the values of fields that administrators have explicitly designated as protected via Class-Level Permissions. The impact is limited to confidentiality — there is no integrity or availability impact — but the boolean oracle technique can be used iteratively (e.g., with $regex patterns) to reconstruct full field values character by character. Any Parse Server class that simultaneously has protectedFields configured and LiveQuery enabled is at risk, potentially exposing sensitive data such as user credentials, tokens, or private application data (Parse Server Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.052% (16th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.
protectedFields configured in their Class-Level Permissions. This may be inferred from application behavior or API responses.wss://<host>/1/events or similar) using the Parse SDK or a raw WebSocket client.{ "where": { "sensitiveField": { "$regex": "^a" } } }.$regex patterns or exact value guesses to reconstruct the full value of the protected field through binary search or character-by-character enumeration.protectedFields; patterns of $regex queries with incrementally changing patterns against a single field.Upgrade Parse Server to version 8.6.35 (for the 8.x branch) or 9.6.0-alpha.9 (for the 9.x branch), both released on March 10, 2026, which add WHERE clause validation against protected fields at subscription creation time (Parse Server 8.6.35 Release, Parse Server 9.6.0-alpha.9 Release). For deployments that cannot be immediately patched, the recommended workarounds are: (1) disable LiveQuery for any class that has protectedFields configured in its Class-Level Permissions, or (2) remove protectedFields restrictions from classes that require LiveQuery functionality. Reviewing and auditing CLP configurations to minimize the intersection of LiveQuery-enabled and protectedFields-configured classes is also advisable (Parse Server Advisory).
The vulnerability was reported and coordinated by mtrezza, a Parse Server maintainer, and disclosed via GitHub Security Advisories on March 10, 2026. The advisory was noted on Bluesky by CVE tracking accounts and security news aggregators shortly after publication. No significant independent researcher commentary or major media coverage has been identified beyond standard CVE tracking and aggregator sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."