SB20260928324 - Incorrect authorization in Parse Server
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose GraphQL schema information.
The vulnerability exists due to incorrect authorization in the GraphQL introspection control when resolving an operation from the automatic persisted query cache. A remote attacker can replay a cached introspection query to disclose GraphQL schema information.
Only deployments with the GraphQL API mounted are affected. Exploitation requires an introspection operation to have previously been registered in the same server process by a client using the master key or maintenance key.
Remediation
Install update from vendor's website.