CVE-2026-33163Disclosure(parseplatform / parse-server)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server leaks protected fields and `authData` to all subscribers of that class. Fields configured as protected via Class-Level Permissions (`protectedFields`) are included in LiveQuery event payloads for all event types (create, update, delete, enter, leave). Any user with sufficient CLP permissions to subscribe to the affected class can receive protected field data of other users, including sensitive personal information and OAuth tokens from third-party authentication providers. The vulnerability was caused by a reference detachment bug. When an `afterEvent` trigger is registered, the LiveQuery server converts the event object to a `Parse.Object` for the trigger, then creates a new JSON copy via `toJSONwithObjects()`. The sensitive data filter was applied to the `Parse.Object` reference, but the unfiltered JSON copy was sent to clients. The fix in versions 9.6.0-alpha.35 and 8.6.50 ensures that the JSON copy is assigned back to the response object before filtering, so the filter operates on the actual data sent to clients. As a workaround, remove all `Parse.Cloud.afterLiveQueryEvent` trigger registrations. Without an `afterEvent` trigger, the reference detachment does not occur and protected fields are correctly filtered.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-19: 1Mentions · 2026-06-20: 1Patch / Workaround · 2026-03-19: 103-1906-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 Parse Server, LiveQuery Access Control Bypass, #CVE-2026-33163 (Medium) -DC-Jun2026-519 https://dailycve.com/parse-server-livequery-access-control-bypass-cve-2026-33163-medium-dc-jun2026-519/

    Post summary

    The post announces the discovery of CVE-2026-33163, a Medium‑severity access control bypass in Parse Server’s LiveQuery, and links to a dailycve.com article.

    0000042
    215 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33163 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `http://Parse.Cloud.afterL… https://www.cve.org/CVERecord?id=CVE-2026-33163

    Post summary

    The text announces a CVE affecting Parse Server in versions earlier than 9.6.0-alpha.35 and 8.6.50, indicating a patch but providing no further technical details.

    00000150
    56.7K followersView on X
CPE platform detail35 entries

35 of 35 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-

Explore more