#VU124975 Missing Authorization in Parse Server - CVE-2026-30850
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the file metadata endpoint when handling requests for file metadata. A remote attacker can send a crafted GET request to disclose sensitive information.
Only user-defined file metadata is exposed; file content remains protected.