Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated remote attacker who knows only the public application ID can submit non-string values in these fields to inject query operators, causing the deduplication cleanup — which runs with elevated privileges before class-level permissions are evaluated — to delete every device registration in the application or an attacker-chosen subset of them. No account, session token, master key, or user interaction is required. Deleted registrations cannot be recovered on the server, so push notifications cannot be delivered until every client re-registers. Any deployment that exposes the REST API to clients and uses push notifications is affected in its default configuration. Versions 8.6.9
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Parse Server versions before 8.6.90 and 9.10.1-alpha.9 contain an unauthenticated NoSQL injection vulnerability in the device token deduplication logic. The vulnerability stems from insufficient input validation on installation record fields, allowing attackers to submit non-string values that are directly incorporated into database queries. An unauthenticated remote attacker with knowledge of only the public application ID can exploit this to inject query operators, potentially leading to unauthorized data access, modification, or deletion. This is particularly critical because the deduplication cleanup runs with elevated privileges, amplifying the impact of successful exploitation. Any organization running affected Parse Server versions in production environments faces significant risk of data breach and system compromise.
While this CVE lacks mapped MITRE ATT&CK techniques, Casky's extended reasoning capabilities would identify attack patterns consistent with CWE-943 (Improper Neutralization of Special Elements in Data Query Logic) by analyzing input handling across the authentication and query processing flows. Practitioners using Casky would observe findings related to injection vulnerabilities, specifically NoSQL injection attempts in application endpoint logs, unusual database query structures in audit trails, and suspicious device token submissions with operator-like payloads. The platform's 754 security skills would flag deviations in query parameter types, unvalidated field values flowing into database operations, and the absence of type-checking middleware on public endpoints—enabling detection of both exploitation attempts and vulnerable code patterns before attacks succeed.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-100631. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation