PT-2026-21833 · Parse · Parse-Dashboard
Byamb4
·
Publicado
2026-02-25
·
Atualizado
2026-03-02
·
CVE-2026-27595
CVSS v4.0
9.9
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Parse Dashboard versions 7.3.0-alpha.42 through 9.0.0-alpha.7
Description
Parse Dashboard, a standalone dashboard for managing Parse Server apps, contains security issues in the AI Agent API endpoint (
/apps/:appId/agent). Versions 7.3.0-alpha.42 through 9.0.0-alpha.7 are affected by multiple vulnerabilities that, when combined, could allow attackers without authentication to perform arbitrary read and write operations on any connected Parse Server database using the master key. The agent feature must be enabled for the dashboard to be affected. The issue stems from a lack of authentication, Cross-Site Request Forgery (CSRF) validation, and per-app authorization on the agent endpoint. A cache key collision between the master key and read-only master key also contributed to the problem.Recommendations
Versions 7.3.0-alpha.42 through 9.0.0-alpha.7: Remove or comment out the agent configuration block from your Parse Dashboard configuration.
Exploit
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Parse-Dashboard