
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33429 is an information disclosure vulnerability in Parse Server's LiveQuery feature, classified as a protected field change detection oracle via the watch parameter. It affects Parse Server (npm) versions prior to 8.6.54 and versions 9.0.0 through 9.6.0-alpha.42 (prior to 9.6.0-alpha.43). The vulnerability was disclosed on March 20, 2026, by maintainer mtrezza, with NVD publication on March 24, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.3 (Medium) (Github Advisory, Parse Server Advisory).
The root cause is an observable discrepancy (CWE-203) in Parse Server's LiveQuery subscription handling. When a client subscribes to LiveQuery using the watch parameter targeting a protected field, the server correctly strips the protected field's value from event payloads — but fails to validate whether the watch parameter itself references a protected field. As a result, the mere presence or absence of update events leaks whether the protected field changed, creating a binary oracle. For boolean protected fields, this is equivalent to knowing the field's exact value. The fix, applied in src/LiveQuery/ParseLiveQueryServer.ts, validates request.query.watch entries against the class's protectedFields at subscription time (mirroring existing where clause validation), rejecting subscriptions that target protected fields — including dot-notation and deeply nested paths — with a Parse.Error.OPERATION_FORBIDDEN error for non-master-key clients (Github Advisory, Patch Commit v9, Patch Commit v8).
Successful exploitation allows an unauthenticated attacker to infer the values of protected fields through side-channel observation of LiveQuery event timing and presence. For boolean protected fields specifically, an attacker can determine the exact field value by monitoring whether update events are emitted. This constitutes unauthorized disclosure of sensitive data that administrators intended to restrict via field-level access controls, with no impact on integrity or availability. The vulnerability is limited to confidentiality of the vulnerable system and does not enable lateral movement or code execution (Github Advisory, Parse Server Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication and no user interaction, making it accessible to any network attacker, though attack requirements (AT:P in CVSS v4) indicate some deployment-specific preconditions. The EPSS score is approximately 0.045% (3rd percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory, Parse Server Advisory).
protectedFields configured (e.g., a SecretClass with protectedFields: { '*': ['secretObj'] }).watch parameter — e.g., query.watch('secretObj') or query.watch('secretObj.apiKey').update events are delivered when objects in the class are modified. The presence of an update event reveals that the protected field changed; absence reveals it did not.secretObj, secretObj.apiKey) in the watch parameter from unauthenticated or low-privilege clients.OPERATION_FORBIDDEN / Permission denied errors on LiveQuery subscribe attempts (post-patch); pre-patch, no error would be logged for these subscriptions, making detection harder. Look for high-frequency LiveQuery subscriptions from a single client IP targeting the same class.Upgrade Parse Server to version 8.6.54 (for the 8.x branch) or 9.6.0-alpha.43 / 9.6.0 (for the 9.x branch) to receive the fix. No configuration-based workarounds are available — the official advisory explicitly states "Workarounds: None." As an additional defense-in-depth measure, review protected field configurations and monitor LiveQuery usage for suspicious subscription patterns targeting protected fields. Master key connections are exempt from the restriction introduced by the patch (Parse Server Advisory, Github Advisory).
The vulnerability was reported and patched by Parse Server maintainer mtrezza, who also authored the fix commits for both the v8 and v9 branches. The fix was released simultaneously with the advisory on March 20, 2026, and included in the stable Parse Server 9.6.0 release on March 22, 2026, alongside a large batch of other security fixes. No significant independent researcher commentary or broad media coverage has been identified beyond the official advisory and standard vulnerability database entries (Parse Server Advisory, PR #10253).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."