{"id":"CVE-2026-27608","title":"Parse Dashboard is a standalone dashboard for managing Parse Server apps","summary":"Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped …","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-862"],"published":"2026-02-25","updated":"2026-06-26","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-27608","references":[{"url":"https://github.com/parse-community/parse-dashboard/releases/tag/9.0.0-alpha.8","label":"security-advisories@github.com"},{"url":"https://github.com/parse-community/parse-dashboard/security/advisories/GHSA-cvwj-6c9h-jg6v","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00221,"epssPercentile":0.12863,"ingestedAt":"2026-06-29T13:24:34.749Z","slug":"CVE-2026-27608","body":"## Overview\n\nParse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to specific apps can access any other app's agent endpoint by changing the app ID in the URL. Read-only users are given the full master key instead of the read-only master key and can supply write permissions in the request body to perform write and delete operations. Only dashboards with `agent` configuration enabled are affected. The fix in version 9.0.0-alpha.8 adds per-app authorization checks and restricts read-only users to the `readOnlyMasterKey` with write permissions stripped server-side. As a workaround, remove the `agent` configuration block from your dashboard configuration. Dashboards without an `agent` config are not affected.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}