CVE-2026-57481: Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber's ACL read access, because leave and enter events included the wrong object state. This issue is fixed in versions 9.9.1-alpha.13 and 8.6.83.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Parse Server (LiveQuery)to a version that resolves this vulnerability.Fixed in 9.9.1-alpha.13 - Upgrade
Upgrade
Parse Server (LiveQuery)to a version that resolves this vulnerability.Fixed in 8.6.83
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57481?
The severity of CVE-2026-57481 is classified as low with a CVSS score of 4.0.
How do I fix CVE-2026-57481?
To fix CVE-2026-57481, upgrade to Parse Server version 9.9.1-alpha.13 or 8.6.83 or later.
What kind of vulnerability is CVE-2026-57481?
CVE-2026-57481 is an info leak vulnerability that allows unauthorized data exposure.
What happens if CVE-2026-57481 is exploited?
If exploited, CVE-2026-57481 allows a LiveQuery subscriber to access object field values they are not authorized to read.
Which software is affected by CVE-2026-57481?
CVE-2026-57481 affects the Parse Server, an open source backend that can be deployed on Node.js.