LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-33163

parseplatform · parse-server

Published
CVSS6.5
Severitymedium
WeaknessCWE-200
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server leaks protected fields and `authData` to all subscribers of that class. Fields configured as protected via Class-Level Permissions (`protectedFields`) are included in LiveQuery event payloads for all event types (create, update, delete, enter, leave). Any user with sufficient CLP permissions to subscribe to the affected class can receive protected field data of other users, including sensitive personal information and OAuth tokens from third-party authenticat

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33163

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33163.