
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33539 is an SQL injection vulnerability in Parse Server's PostgreSQL storage adapter that allows an attacker with master key access to execute arbitrary SQL statements against the underlying PostgreSQL database. It affects all Parse Server versions prior to 8.6.59 and versions 9.0.0 through 9.6.0-alpha.52 running on Node.js with a PostgreSQL backend; MongoDB deployments are not affected. The vulnerability was disclosed on March 21, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory).
The root cause is improper neutralization of SQL special characters (CWE-89) in the PostgreSQL storage adapter's transformAggregateField() and distinct() functions. Field name parameters supplied to the aggregate $group._id pipeline stage and the distinct operation were passed directly into SQL queries via :raw interpolation without sanitization, allowing SQL metacharacters (e.g., double quotes, semicolons) to break out of the intended query context. The fix introduced a validateAggregateFieldName() helper enforcing the regex /^[a-zA-Z][a-zA-Z0-9_]*$/ on each field name segment, rejecting any input containing SQL-unsafe characters with a Parse.Error.INVALID_KEY_NAME error (GitHub Advisory, Fix PR #10272, Fix PR #10273).
Successful exploitation allows a Parse Server application-level administrator (master key holder) to escalate privileges to full PostgreSQL database-level access, enabling arbitrary SQL execution. This can result in complete compromise of the database — including unauthorized reading, modification, or deletion of all stored data — as well as potential creation of backdoors, disruption of database availability, or lateral movement to other systems accessible from the database host. The confidentiality, integrity, and availability of the PostgreSQL database are all fully impacted (GitHub Advisory).
Exploitation requires possession of the Parse Server master key, which limits the attack surface to application-level administrators. No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.046% (very low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
GET /1/aggregate/<ClassName> or using the distinct query parameter.$group._id field value that embeds SQL metacharacters, e.g.:GET /1/aggregate/TestClass
Headers: X-Parse-Master-Key: <master_key>
Query: pipeline=[{"$group":{"_id":{"alias":"$playerName\" OR 1=1 --"}}}]distinct parameter with a dot-notation field name containing SQL metacharacters, e.g., distinct=metadata" FROM pg_tables; --.tag.:raw SQL interpolation context in the PostgreSQL adapter, causing the database to execute attacker-controlled SQL statements — enabling data exfiltration, schema manipulation, or privilege escalation within PostgreSQL (GitHub Advisory, Fix Commit)./1/aggregate/<ClassName> endpoints containing SQL metacharacters (e.g., ", ;, ', --, OR 1=1) in pipeline or distinct query parameters; requests authenticated with the master key from unexpected IP addresses.[a-zA-Z0-9_.]); PostgreSQL query logs showing unexpected SQL statements such as DROP TABLE, SELECT * FROM pg_tables, or tautological conditions like OR 1=1.pg_stat_activity or query logs originating from the Parse Server database user.Upgrade Parse Server to version 8.6.59 (for the 8.x LTS line) or 9.6.0-alpha.53 or later (for the 9.x line); no configuration-based workaround exists. Additionally, restrict master key access to the minimum number of trusted administrators, implement network segmentation to limit direct PostgreSQL access, and monitor database logs for anomalous SQL query patterns. Review access logs for unauthorized or unexpected use of the master key (GitHub Advisory, Fix PR #10273).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."