SB2026040766 - Incorrect authorization in Parse Server
Published: April 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect authorization (CVE-ID: CVE-2026-30947)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in LiveQuery subscriptions when handling subscription requests and event delivery. A remote attacker can subscribe to a LiveQuery-enabled class without authorization checks to disclose sensitive information.
Data restricted by class-level permissions can be leaked to unauthorized subscribers in real time.
Remediation
Install update from vendor's website.