{"id":"CVE-2026-34595","title":"Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js","summary":"Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields cl…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-843"],"vendor":"parseplatform","product":"parse-server","affected":["parse-server < 8.6.70","parse-server >= 9.0.0, < 9.7.0","parse-server = 9.7.0"],"patched":["parse-server 9.7.0"],"published":"2026-03-31","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-34595","references":[{"url":"https://github.com/parse-community/parse-server/commit/f63fd1a3fe0a7c1c5fe809f01b0e04759e8c9b98","label":"security-advisories@github.com"},{"url":"https://github.com/parse-community/parse-server/commit/ffad0ec6b971ee0dd9545e1bf1fb34ddebf275c2","label":"security-advisories@github.com"},{"url":"https://github.com/parse-community/parse-server/pull/10350","label":"security-advisories@github.com"},{"url":"https://github.com/parse-community/parse-server/pull/10351","label":"security-advisories@github.com"},{"url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00251,"epssPercentile":0.16903,"ingestedAt":"2026-07-24T20:38:02.595Z","slug":"CVE-2026-34595","body":"## Overview\n\nParse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery subscriptions. By sending a subscription with a $or, $and, or $nor operator value as a plain object with numeric keys and a length property (an \"array-like\" object) instead of an array, the protected-field guard is bypassed. The subscription event firing acts as a binary oracle, allowing the attacker to infer whether a protected field matches a given test value. This issue has been patched in versions 8.6.70 and 9.7.0-alpha.18.\n\n## Affected\n\n- `parse-server < 8.6.70`\n- `parse-server >= 9.0.0, < 9.7.0`\n- `parse-server = 9.7.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `parse-server 9.7.0`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}