CVE-2026-57481
published 2026-07-08CVE-2026-57481: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery…
PriorityP417low2.3CVSS 4.0
AVNACLATPPRLUINVCLVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.53%
43.6th percentile
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber's ACL read access, because leave and enter events included the wrong object state. This issue is fixed in versions 9.9.1-alpha.13 and 8.6.83.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| parse-community | parse-server | < 8.6.83 | 8.6.83 |
| parse-community | parse-server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/parse-community/parse-server/commit/c9b24cecfee76d8563019adaacbcbd78471dc41ehttps://github.com/parse-community/parse-server/commit/e9c85dfe40a866a55ebae3b6ae56285ac0a22e64https://github.com/parse-community/parse-server/pull/10515https://github.com/parse-community/parse-server/pull/10516https://github.com/parse-community/parse-server/releases/tag/8.6.83https://github.com/parse-community/parse-server/releases/tag/9.9.1-alpha.13https://github.com/parse-community/parse-server/security/advisories/GHSA-97pr-9hgg-3p8r
2026-07-08
Published