CVE-2026-105828
Received Received - Intake

Information Disclosure in Parse Server via GraphQL Errors

Vulnerability report for CVE-2026-105828, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
parse-community parse-server 9.0.0
parse-community parse-server 8.2.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Parse Server versions 8.2.2 to 8.6.91 and 9.0.0 to 9.10.1-alpha.11 allows unauthenticated attackers with only the public Application ID to send crafted GraphQL operations that trigger validation errors. These errors reveal hidden class names, specifically pointer and relation target classes, even when public introspection is disabled.

Detection Guidance

To detect this vulnerability, monitor GraphQL error responses for class name disclosures in validation errors. Check if error messages reveal hidden class names when public introspection is disabled. Review Parse Server logs for unknown-argument or invalid enum value errors that expose class names.

Impact Analysis

The impact is limited to information disclosure. Attackers can learn about hidden class names in the database schema but cannot access object data, credentials, session tokens, or configuration values. The vulnerability does not modify data or affect system availability.

Compliance Impact

This vulnerability may pose compliance risks under GDPR and HIPAA due to unauthorized information disclosure. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. The exposure of schema details could indicate insufficient data protection measures.

Mitigation Strategies

Immediately upgrade Parse Server to versions 9.10.1-alpha.12 or 8.6.92. If GraphQL API is not required, disable it. Restrict network access to trusted clients only. Review class permissions to ensure access controls remain intact.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105828. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart