SB20260928324 - Incorrect authorization in Parse Server



SB20260928324 - Incorrect authorization in Parse Server

Published: September 28, 2026

Security Bulletin ID SB20260928324
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose GraphQL schema information.

The vulnerability exists due to incorrect authorization in the GraphQL introspection control when resolving an operation from the automatic persisted query cache. A remote attacker can replay a cached introspection query to disclose GraphQL schema information.

Only deployments with the GraphQL API mounted are affected. Exploitation requires an introspection operation to have previously been registered in the same server process by a client using the master key or maintenance key.


Remediation

Install update from vendor's website.