---
id: CVE-2026-105828
title: >-
  Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an
  information disclosure vulnerability in which GraphQL validation error
  messages reveal hidden class names when public introspection is disabled
summary: >-
  Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an
  information disclosure vulnerability in which GraphQL validation error
  messages reveal hidden class names when public introspection is disabled.
  Unauthenticate…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-209
vendor: parse-community
product: parse-server
affected:
  - parse-server >= 9.0.0 < 9.10.1-alpha.12
  - parse-server >= 8.2.2 < 8.6.92
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:35:34.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105828'
references:
  - url: >-
      https://github.com/parse-community/parse-server/security/advisories/GHSA-6m77-f8xr-f723
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/parse-server-9.0.0-before-9.10.1-alpha.12-class-name-disclosure-via-graphql-errors
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-08T18:11:32.734902Z'
cvssSource: cna
ingestedAt: '2026-10-08T14:47:16.360Z'
---

## Overview

Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
