CVE-2026-34595Medium· 4.3▾ SunlitParse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields cl…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery subscriptions. By sending a subscription with a $or, $and, or $nor operator value as a plain object with numeric keys and a length property (an "array-like" object) instead of an array, the protected-field guard is bypassed. The subscription event firing acts as a binary oracle, allowing the attacker to infer whether a protected field matches a given test value. This issue has been patched in versions 8.6.70 and 9.7.0-alpha.18.
parse-server < 8.6.70parse-server >= 9.0.0, < 9.7.0parse-server = 9.7.0Upgrade past the affected range:
parse-server 9.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87806High· 7.4Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter
CVE-2026-34373High· 8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34363Medium· 5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34224Medium· 4.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34574Medium· 5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34573High· 7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js