
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33421 is an incorrect authorization vulnerability in Parse Server's LiveQuery WebSocket interface that allows authenticated users to bypass Class-Level Permission (CLP) pointer permissions (readUserFields and pointerFields). Any authenticated user can subscribe to LiveQuery events and receive real-time updates for all objects in pointer-permission-protected classes, regardless of whether those objects' pointer fields reference the subscribing user. The vulnerability affects Parse Server (npm) versions < 8.6.53 and >= 9.0.0, < 9.6.0-alpha.42 running on Node.js. It was published on March 20, 2026, and assigned a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, Parse Server Advisory).
The root cause is CWE-863 (Incorrect Authorization): the LiveQuery server's existing CLP check deferred pointer permission evaluation by design, but never subsequently enforced it, meaning the check was effectively skipped for WebSocket-based subscriptions. When an object is created or updated, the LiveQuery server broadcasts events to all subscribers without verifying whether the subscribing user is referenced by the configured pointer fields (readUserFields or pointerFields) on that object. The attack vector is network-based, requires low privileges (a valid authenticated session), and no user interaction. The fix, applied in src/LiveQuery/ParseLiveQueryServer.ts, adds a post-check in _matchesCLP that resolves the subscriber's user ID from their session token and verifies that at least one configured pointer field on the object references that user before delivering the event; non-matching events are silently skipped, consistent with ACL mismatch handling (GitHub Advisory, Fix Commit v9, Fix Commit v8).
Exploitation results in a high-confidentiality-impact breach with no integrity or availability impact. An authenticated attacker can receive real-time data updates for all objects in any class protected by CLP pointer permissions — data that is correctly restricted when accessed via the REST API. This could expose sensitive user-specific data (e.g., private messages, personal documents, or records with restricted ownership fields) to any authenticated user in the application, potentially affecting all users' private data across all pointer-permission-protected classes (GitHub Advisory, Parse Server Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.01% (2nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid authenticated account, making it accessible to any registered user of an affected Parse Server application (GitHub Advisory, Feedly).
liveQuery.classNames option). These are often the same classes used by the application's real-time features.ws://<host>/1 or wss://<host>/1) using the Parse SDK or a raw WebSocket client, authenticating with the obtained session token.PrivateMessage) without any query filters. On unpatched servers, the CLP pointer permission check is not enforced, so the subscription is accepted regardless of the class's readUserFields or pointerFields configuration.create, update, enter, and leave events — including full object data — for objects whose pointer fields do not reference the attacker, exposing data that the REST API would correctly deny (GitHub Advisory, Parse Server Advisory).ws:// or wss://) from user accounts that do not normally use real-time features; subscriptions to classes containing sensitive data from accounts that should not have access.GET /1 with Upgrade: websocket) from unexpected client IPs or user accounts; LiveQuery subscription messages for pointer-permission-protected class names from users not referenced in those classes' pointer fields.Upgrade immediately to one of the patched versions:
Patches are available via npm: npm install parse-server@8.6.53 or npm install parse-server@9.6.0.
Workaround (if immediate patching is not possible): Replace or supplement CLP pointer permissions with object-level ACLs on individual objects. ACLs are correctly enforced by the LiveQuery server and will prevent unauthorized event delivery. Additionally, consider implementing network-level restrictions on LiveQuery WebSocket access and reviewing access logs for unusual subscription patterns (GitHub Advisory, Parse Server Advisory).
The vulnerability was reported and coordinated by Parse Server maintainer mtrezza, who also authored the fix. The advisory was published through GitHub's security advisory process (GHSA-fph2-r4qg-9576) on March 20, 2026, and the fix was merged and released the same day. No significant external researcher commentary or broad media coverage has been identified beyond standard vulnerability database entries (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."