#VU124999 Information disclosure in Parse Server - CVE-2026-32098
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the LiveQuery subscription WHERE clause handling when creating LiveQuery subscriptions that reference protected fields. A remote attacker can send a specially crafted subscription query to disclose sensitive information.
Only classes that have both protectedFields configured in class-level permissions and LiveQuery enabled are vulnerable.