CVE-2026-31872 | parse-community parse-server up to 8.6.31/9.0.0 9.6.0-alpha.5 protectedFields sort access control (GHSA-r2m8-pxm9-9c4g)
A vulnerability was found in parse-community parse-server up to 8.6.31/9.0.0 9.6.0-alpha.5. It has been declared as critical. Affected by this vulnerability is the function protectedFields. Executing a manipulation of the argument sort can lead to improper access controls.
This vulnerability is tracked as CVE-2026-31872. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.