Incorrect authorization in Parse Server - #VU152593

 

Incorrect authorization in Parse Server - #VU152593

Published: September 28, 2026


Vulnerability identifier: #VU152593
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose GraphQL schema information.

The vulnerability exists due to incorrect authorization in the GraphQL introspection control when resolving an operation from the automatic persisted query cache. A remote attacker can replay a cached introspection query to disclose GraphQL schema information.

Only deployments with the GraphQL API mounted are affected. Exploitation requires an introspection operation to have previously been registered in the same server process by a client using the master key or maintenance key.


Affected software

Parse Server

Remediation

Install security update from vendor's website.

Parse Server - addressed in versions 8.6.94, 9.10.1 alpha.14

External References

Related Security Bulletins