CVE-2026-56783 Details
Description
Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and basic-auth credentials in cleartext due to commented-out secret-masking functionality. Any authenticated user with the GetAlert action, including low-privilege reader roles, can recover credentials and internal endpoint URLs for all configured notification targets by querying GET /api/v1/targets or related endpoints.
A cleartext credential exposure vulnerability has been identified in Parseable versions prior to 2.9.2. This issue resides within the notification-target API endpoints, which improperly disclose webhook tokens and basic-auth credentials. The vulnerability arises from a secret-masking feature that was intended to be active but instead left commented out, allowing sensitive information to be transmitted in plain text. Any authenticated user with the GetAlert permission, including those with low-privilege reader roles, can exploit this vulnerability. By accessing the GET /api/v1/targets endpoint or related API calls, these users can retrieve credentials and internal URLs for all notification targets configured within their tenant.
Users can upgrade to Parseable version 2.9.2 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/parseablehq/parseable/issues/1693 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/parseablehq/parseable/commit/f307c4989cc9f3ff4204fd383dec7a39924e6b2a | [email protected] | Source CodeVendor |
| https://github.com/parseablehq/parseable/issues/1693 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/parseablehq/parseable/pull/1698 | [email protected] | Issue TrackingVendor |
| https://github.com/parseablehq/parseable/releases/tag/v2.9.2 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/parseable-cleartext-credential-exposure-in-notification-target-api | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Parseable | < 2.9.2 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 29, 2026 | New CVE Received | [email protected] |
Volerion