What is CVE-2026-66009?
This vulnerability in Parse Server exposes the names of required custom input fields in GraphQL error messages, even when public introspection is disabled. An attacker with only the public application ID can abuse this to discover the internal data schema. Developers should immediately upgrade to the patched versions (beyond 8.6.86 for the 8.x branch or beyond 9.10.0-alpha.5 for the 9.x branch).
Azərbaycanca: Parse Server-də aşkar edilmiş bu boşluq, GraphQL sorğularında ictimai introspeksiya (`graphQLPublicIntrospection`) söndürülsə belə, xəta mesajlarında tələb olunan xüsusi giriş sahələrinin adlarının (`custom input fields`) açıqlanmasına səbəb olur. Bu, sadəcə tətbiqin ictimai identifikatoruna (`public application id`) malik olan hücumçuya daxili verilənlər modeli haqqında məlumat əldə etməyə imkan yaradır. Tərtibatçılar dərhal təsirlənmiş versiyaları (8.2.2 - 8.6.86 arası və 9.0.0 - 9.10.0-alpha.5 arası) yamalı versiyalara yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What does an attacker need to exploit CVE-2026-66009?
An attacker only needs the public application ID.
Which feature can be bypassed by CVE-2026-66009 to leak information?
Even when `graphQLPublicIntrospection` is disabled, the names of required custom input fields are disclosed in GraphQL error messages.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.