Junglewise Threat Intelligence

CVE-2026-53726: Parse Server authorization bypass in $relatedTo queries

CVE-2026-53726 · Severity: medium · CVSS 4 · Published 2026-06-12

Technologies: Parse Community Parse-Server. Vendors: Parse Community.

Executive brief

Parse Server is an open-source backend framework used to build and host web and mobile applications. A security flaw allowed unauthorized users to bypass privacy settings and view relationships between data objects that should have been hidden. This could lead to the exposure of sensitive information such as private group memberships, block lists, or internal account associations.

Technical details

A vulnerability in the `$relatedTo` query operator allows for an authorization bypass (CWE-639). The root cause is that the relation query path failed to validate the caller's authentication context against the owning object's ACLs or the class's `protectedFields` before querying the join table. An unauthenticated attacker with knowledge of a target `objectId` can use this to enumerate linked objects or perform a membership oracle attack to confirm if a specific object is linked to a private parent. The issue is fixed in versions 8.6.80 and 9.9.1-alpha.6 by enforcing authorization checks on the owning object and its fields before returning results.

Affected products

  • Parse Community parse-server >= 9.0.0, < 9.9.1-alpha.6; < 8.6.80

Timeline

  • 2026-06-04: disclosed: Initial disclosure to the vendor
  • 2026-06-12: advisory: NVD publication date
  • 2026-06-19: advisory: GitHub Advisory published

References