CVE-2026-31871 is a critical SQL injection vulnerability impacting Parse Server versions prior to 9.6.0-alpha.5 and 8.6.31 when utilizing a PostgreSQL database. The flaw arises from improper handling of sub-key names in Increment operations on nested object fields, allowing an attacker to inject arbitrary SQL via the REST API. With a CVSS score of 9.8 (Critical), this vulnerability enables unauthenticated attackers to potentially execute commands, read sensitive data, and bypass security controls. While the attack complexity is low, there is currently no evidence of active exploitation, public exploit code, or significant community discussion. Organizations using affected Parse Server versions with PostgreSQL should upgrade immediately to mitigate this high-severity risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.31CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
>= 9.0.0, < 9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha1:*:*:*:node.js:*:* | ||
9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha2:*:*:*:node.js:*:* | ||
9.6.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha3:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.