PT-2026-24689 · Bitnami+4 · Parse+1

Restriction

·

Published

2026-03-11

·

Updated

2026-03-13

·

CVE-2026-31872

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.6.0-alpha.6 Parse Server versions prior to 8.6.32
Description Parse Server is an open source backend deployable on Node.js infrastructures. A flaw exists in the class-level permission (CLP) feature, specifically with the protectedFields setting. An attacker can bypass this protection by utilizing dot-notation within query WHERE clauses and sort parameters. This allows querying or sorting by sub-fields of a protected field, potentially enabling a binary oracle attack to reveal values of those protected fields. This issue impacts both MongoDB and PostgreSQL deployments. The vulnerability is related to how query keys and sort keys are checked against protected fields, failing to extract the root field from dot-notation paths. For example, a query on secretObj.apiKey was not correctly blocked when secretObj was a protected field.
Recommendations Versions prior to 9.6.0-alpha.6 should be updated to version 9.6.0-alpha.6 or later. Versions prior to 8.6.32 should be updated to version 8.6.32 or later.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-31872
CVE-2026-31872
GHSA-R2M8-PXM9-9C4G

Affected Products

Parse
Parse Server