Information disclosure in Parse Server - #VU149932
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to disclose protected field values.
The vulnerability exists due to improper authorization caused by incomplete subscriber identity resolution in LiveQuery protectedFields permission evaluation when handling LiveQuery subscriptions. A remote user can create a subscription to receive field values withheld by the REST API.
Applications are affected when LiveQuery is enabled on a class using protectedFields for role, authenticated, or per-user groups.