SB2026040756 - Information disclosure in Parse Server
Published: April 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2026-32098)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the LiveQuery subscription WHERE clause handling when creating LiveQuery subscriptions that reference protected fields. A remote attacker can send a specially crafted subscription query to disclose sensitive information.
Only classes that have both protectedFields configured in class-level permissions and LiveQuery enabled are vulnerable.
Remediation
Install update from vendor's website.