---
id: CVE-2026-27608
title: Parse Dashboard is a standalone dashboard for managing Parse Server apps
summary: >-
  Parse Dashboard is a standalone dashboard for managing Parse Server apps. In
  versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint
  (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated
  users scoped …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
published: '2026-02-25'
updated: '2026-06-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27608'
references:
  - url: >-
      https://github.com/parse-community/parse-dashboard/releases/tag/9.0.0-alpha.8
    label: security-advisories@github.com
  - url: >-
      https://github.com/parse-community/parse-dashboard/security/advisories/GHSA-cvwj-6c9h-jg6v
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00378
epssPercentile: 0.29
ingestedAt: '2026-06-29T13:24:34.749Z'
---

## Overview

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to specific apps can access any other app's agent endpoint by changing the app ID in the URL. Read-only users are given the full master key instead of the read-only master key and can supply write permissions in the request body to perform write and delete operations. Only dashboards with `agent` configuration enabled are affected. The fix in version 9.0.0-alpha.8 adds per-app authorization checks and restricts read-only users to the `readOnlyMasterKey` with write permissions stripped server-side. As a workaround, remove the `agent` configuration block from your dashboard configuration. Dashboards without an `agent` config are not affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
