Executive brief
Parse Server is a backend-as-a-service platform that manages data and real-time notifications. An attacker can watch protected fields through LiveQuery subscriptions to infer whether sensitive data has changed, bypassing field-level access controls through timing and event presence analysis. While the actual field values remain hidden, this creates a side-channel leak of sensitive information about protected fields.
Technical details
The vulnerability is an information disclosure oracle (CWE-203) in Parse Server's LiveQuery implementation. An attacker can subscribe to real-time change events using the watch parameter to monitor protected fields that should be inaccessible. Although the protected field values are correctly stripped from event payloads, the presence or absence of update events—and their timing for boolean fields—reveals whether the protected field changed, creating a binary oracle. The attack requires network access to the LiveQuery endpoint but no authentication. The patch validates the watch parameter against protected fields at subscription time and rejects unauthorized subscriptions with a permission error.
Affected products
- Parse Community Parse Server 0 to 8.6.53, 9.0.0 to 9.6.0-alpha.42
Timeline
- 2026-03-20: disclosed: Security advisory published by Parse Community
- 2026-03-20: patched: Fixed in Parse Server 9.6.0-alpha.43 and 8.6.54