CVE-2026-31856 describes a critical SQL injection vulnerability affecting Parse Server's PostgreSQL storage adapter when processing Increment operations on nested object fields. This flaw specifically impacts Parse Server deployments using PostgreSQL, with MongoDB deployments remaining unaffected. With a CVSS score of 9.8 Critical (AV:N/AC:L/PR:N), an unauthenticated attacker can exploit this vulnerability to inject arbitrary SQL subqueries, leading to full data compromise by bypassing all confidentiality, integrity, and access controls. Despite its severe impact and ease of exploitation, there is currently no evidence of active exploitation, public exploit code availability, or significant community discussion surrounding CVE-2026-31856.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.29CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
>= 9.0.0, < 9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha1:*:*:*:node.js:*:* | ||
9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha2:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.