#VU124992 Improper access control in Parse Server - CVE-2026-30962
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in protected fields validation when processing query constraints inside logical operators. A remote user can send a specially crafted query to disclose sensitive information.
All deployments have default protected fields that are vulnerable.