Medium severityNVD Advisory· Published Oct 8, 2026
CVE-2026-105828
CVE-2026-105828
Description
Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes.
Affected products
1- Range: <8.6.92, <9.10.1-alpha.12
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.