Executive brief
Parse Server is a backend framework for building scalable applications. The readOnlyMasterKey feature is supposed to allow read-only access while preventing all write operations. However, a flaw allows attackers who possess the readOnlyMasterKey to create, modify, and delete Cloud Hooks and trigger Cloud Jobs—capabilities that should be restricted. This can lead to data exfiltration and unauthorized modifications to the application's configuration.
Technical details
This is an authorization bypass vulnerability (CWE-863) in Parse Server's Cloud Hooks and Cloud Jobs endpoints. The readOnlyMasterKey is intended to restrict API access to read-only operations, but several mutating endpoints incorrectly accept and process requests authenticated with this key. An attacker who knows the readOnlyMasterKey can invoke write operations to create/modify/delete Cloud Hooks and start Cloud Jobs, bypassing the intended privilege restrictions. The vulnerability requires knowledge of the readOnlyMasterKey to exploit; patches add proper authorization checks to reject mutating requests authenticated with readOnlyMasterKey. Versions prior to 8.6.4 and 9.0.0 through 9.4.1-alpha.2 are affected.
Affected products
- Parse Community Parse Server < 8.6.4 and >= 9.0.0, <= 9.4.1-alpha.2
Timeline
- 2026-03-04: disclosed
- 2026-03-05: patched: Patched in versions 8.6.4 and 9.4.1-alpha.3