SB2026040763 - Improper access control in Parse Server
Published: April 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2026-30962)
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in protected fields validation when processing query constraints inside logical operators. A remote user can send a specially crafted query to disclose sensitive information.
All deployments have default protected fields that are vulnerable.
Remediation
Install update from vendor's website.