PT-2026-21833 · Parse · Parse-Dashboard

Byamb4

·

Published

2026-02-25

·

Updated

2026-03-02

·

CVE-2026-27595

CVSS v4.0

9.9

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Parse Dashboard versions 7.3.0-alpha.42 through 9.0.0-alpha.7
Description Parse Dashboard, a standalone dashboard for managing Parse Server apps, contains security issues in the AI Agent API endpoint (/apps/:appId/agent). Versions 7.3.0-alpha.42 through 9.0.0-alpha.7 are affected by multiple vulnerabilities that, when combined, could allow attackers without authentication to perform arbitrary read and write operations on any connected Parse Server database using the master key. The agent feature must be enabled for the dashboard to be affected. The issue stems from a lack of authentication, Cross-Site Request Forgery (CSRF) validation, and per-app authorization on the agent endpoint. A cache key collision between the master key and read-only master key also contributed to the problem.
Recommendations Versions 7.3.0-alpha.42 through 9.0.0-alpha.7: Remove or comment out the agent configuration block from your Parse Dashboard configuration.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-27595
GHSA-QWC3-H9MG-4582

Affected Products

Parse-Dashboard