{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aparseplatformparse-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-100631"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Parse Server (\u003c 8.6.90, 9.0.0 \u003c= v \u003c 9.10.1-alpha.9)"],"_cs_severities":["medium"],"_cs_tags":["cve-2026-100631","injection","nosql-injection","denial-of-service"],"_cs_type":"advisory","_cs_vendors":["Parse"],"content_html":"\u003cp\u003eParse Server (versions prior to 8.6.90 and 9.0.0 through 9.10.1-alpha.8) is vulnerable to a NoSQL query injection attack within its device token deduplication mechanism. The vulnerability exists because the application fails to validate the data type of client-supplied installation fields before using them to construct database queries. An unauthenticated remote attacker possessing only the public application ID can provide non-string values (such as objects or arrays) within these fields, causing the deduplication cleanup process to execute malicious query logic. Because this cleanup process runs with elevated privileges before standard class-level permissions are validated, an attacker can delete all device registration records associated with an application or specific subsets defined by the injected criteria. This disruption effectively prevents the delivery of push notifications to affected users, and because the data is purged, recovery is only possible through client-side re-registration. No account access or master keys are required to trigger this impact, making it a critical availability risk for any deployment exposing the REST API.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an internet-facing Parse Server deployment exposing the REST API.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the public application ID to target the specific instance.\u003c/li\u003e\n\u003cli\u003eThe attacker constructs a malicious HTTP request targeting the installation deduplication endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker provides non-string data (e.g., JSON objects containing query operators like '$ne' or '$in') within the device token installation fields.\u003c/li\u003e\n\u003cli\u003eThe Parse Server backend receives the request and triggers the deduplication cleanup logic.\u003c/li\u003e\n\u003cli\u003eThe database driver interprets the injected query operators due to improper type validation.\u003c/li\u003e\n\u003cli\u003eThe system executes the modified query with elevated, administrative-level privileges, bypassing class-level permission checks.\u003c/li\u003e\n\u003cli\u003eThe database performs an unauthorized delete operation, purging targeted device registration records and disabling push notifications.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability results in the permanent loss of device registration records for the affected Parse Server application. This leads to a total service outage for push notification functionality across the targeted installation. Because the records are deleted from the database without server-side backups available for restoration, legitimate users must manually re-register their devices to regain push notification services. This vulnerability affects all deployments that expose the REST API and utilize push notifications in their default configuration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Parse Server to version 8.6.90 or 9.10.1-alpha.9 immediately to incorporate the required input type validation and cleanup scoping.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for HTTP requests directed at installation endpoints that contain non-string data or unconventional JSON structures in installation fields, as these may indicate exploitation attempts.\u003c/li\u003e\n\u003cli\u003eImplement strict API gateway-level validation or WAF rules to reject requests containing non-string data types in fields expected to be strictly string-based.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-26T15:03:28Z","date_published":"2026-09-26T15:03:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-parse-server-injection/","summary":"A vulnerability in Parse Server's device token deduplication logic allows unauthenticated remote attackers to inject NoSQL query operators, leading to unauthorized deletion of device registrations.","title":"Unauthenticated Query Injection in Parse Server Device Token Deduplication","url":"https://feed.craftedsignal.io/briefs/2026-09-parse-server-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:parseplatform:parse-Server:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}