VYPR
High severity7.5NVD Advisory· Published Mar 10, 2026· Updated Jun 17, 2026

CVE-2026-30947

CVE-2026-30947

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-level permissions (CLP) are not enforced for LiveQuery subscriptions. An unauthenticated or unauthorized client can subscribe to any LiveQuery-enabled class and receive real-time events for all objects, regardless of CLP restrictions. All Parse Server deployments that use LiveQuery with class-level permissions are affected. Data intended to be restricted by CLP is leaked to unauthorized subscribers in real time. This vulnerability is fixed in 9.5.2-alpha.3 and 8.6.16.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
parse-servernpm
>= 9.0.0, < 9.5.2-alpha.39.5.2-alpha.3
parse-servernpm
< 8.6.168.6.16

Affected products

6
  • cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*+ 2 more
    • cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*range: <8.6.16
    • cpe:2.3:a:parseplatform:parse-server:9.5.2:alpha1:*:*:*:node.js:*:*
    • cpe:2.3:a:parseplatform:parse-server:9.5.2:alpha2:*:*:*:node.js:*:*
  • osv-coords2 versions
    < 8.6.16+ 1 more
    • (no CPE)range: < 8.6.16
    • (no CPE)range: >= 9.0.0, < 9.5.2-alpha.3
  • Range: >= 9.0.0 < 9.5.2-alpha.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.