CVE-2026-53726
Last modified
CVE-2026-53726 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation field even when that field was hidden from the requesting client by protectedFields, and even when the object owning the relation was not readable by the client under its ACL or class-level permissions. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation field even when that field was hidden from the requesting client by protectedFields, and even when the object owning the relation was not readable by the client under its ACL or class-level permissions. The request requires only the public API credentials that Parse clients normally carry — no user session, master key, or Cloud Code is needed. As a result, an unauthenticated client who knows or obtains the owning object's objectId could enumerate the objects linked through a protected relation, or combine the operator with an objectId constraint to use it as a membership oracle — confirming whether a specific object is linked to a private parent. This affects applications that rely on protectedFields or object ACLs to keep Relation membership confidential, such as private group memberships, block lists, or account-to-resource associations. This issue has been patched in versions 8.6.80 and 9.9.1-alpha.6.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53726?
How severe is CVE-2026-53726?
How do I fix CVE-2026-53726?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5372An issue that allowed a SQL injection attack vector related …6.4
- CVE-2026-53721Nuxt is an open-source web development framework for Vue.js.…8.2
- CVE-2026-53722Nuxt is an open-source web development framework for Vue.js.…5.4
- CVE-2026-53723Guzzle Services provides an implementation of the Guzzle Com…5.8
- CVE-2026-53724Parse Server is an open source backend that can be deployed …2.1
- CVE-2026-53725Parse Server is an open source backend that can be deployed …5.9
- CVE-2026-53727css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, Css…8.9
- CVE-2026-53729DataEase is an open source data visualization and analysis t…8.7
- CVE-2026-5373An issue that allowed all-organization administrators to pro…8.4
- CVE-2026-53730DataEase is an open source data visualization and analysis t…8.7
- CVE-2026-53736Easy Twitter Feeds before 1.2.13 contains a cross-site reque…5.1
- CVE-2026-53737Juicer through 1.12.18 fails to escape remote feed API respo…6.1
Are you affected by CVE-2026-53726?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
