PT-2026-24689 · Bitnami+4 · Parse+1

·

CVE-2026-31872

·

Publicado

2026-03-11

·

Atualizado

2026-03-13

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.6.0-alpha.6 Parse Server versions prior to 8.6.32
Description Parse Server is an open source backend deployable on Node.js infrastructures. A flaw exists in the class-level permission (CLP) feature, specifically with the protectedFields setting. An attacker can bypass this protection by utilizing dot-notation within query WHERE clauses and sort parameters. This allows querying or sorting by sub-fields of a protected field, potentially enabling a binary oracle attack to reveal values of those protected fields. This issue impacts both MongoDB and PostgreSQL deployments. The vulnerability is related to how query keys and sort keys are checked against protected fields, failing to extract the root field from dot-notation paths. For example, a query on secretObj.apiKey was not correctly blocked when secretObj was a protected field.
Recommendations Versions prior to 9.6.0-alpha.6 should be updated to version 9.6.0-alpha.6 or later. Versions prior to 8.6.32 should be updated to version 8.6.32 or later.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-PARSE-2026-31872
CVE-2026-31872
GHSA-R2M8-PXM9-9C4G

Produtos afetados

Parse
Parse Server